Техническая информация
- [<HKLM>\System\CurrentControlSet\Services\atmlib] 'Start' = '00000002'
- [<HKLM>\System\CurrentControlSet\Services\atmlib] 'ImagePath' = '"%WINDIR%\SysWOW64\cryptnet\atmlib.exe"'
- 'atmlib' "%WINDIR%\SysWOW64\cryptnet\atmlib.exe"
- 'atmlib' %WINDIR%\SysWOW64\cryptnet\atmlib.exe
- из <Полный путь к файлу> в %WINDIR%\syswow64\cryptnet\atmlib.exe
- '15#.#86.9.160':80
- '5.#.212.254':80
- '64.##7.182.168':8080
- '51.##.36.180':443
- http://15#.#86.9.160/WydCRZKGC9YCwv/UEuKI0vM/14LHzgiDwU0Lt/xJqV4crN/iOuTKR8GqPs/
- http://64.###.182.168:8080/sxw1Ti0fG/gVahVq3iizE7w4/PlpuL/2sq3bs9j/ via 64.##7.182.168
- http://51.##.36.180:443/Ikx85iNYjTvxr/dPUKdrg03K/QWdPUawsXzbYr3w4/KQlPDUDtPM6N/ via 51.##.36.180