Техническая информация
- %APPDATA%\microsoft\windows\start menu\programs\startup\sbishwcu.lnk
- <SYSTEM32>\tasks\opera scheduled autoupdate 3131961357
- '' (загружен из сети Интернет)
- 'C:\users\public\69577.exe'
- https://u.teknik.io/u6ssu.txt как %temp%\yvetqqyefi.exe
- C:\users\public\69577.exe
- %TEMP%\yvetqqyefi.exe
- %APPDATA%\microsoft\windows\sbishwcu\hduaurtt.exe
- %APPDATA%\microsoft\windows\sbishwcu\hduaurtt.exe
- %TEMP%\yvetqqyefi.exe
- 'bi#.ly':80
- 'pr######eathleticsinc.com':80
- 'u.##knik.io':443
- 'ms###csi.com':80
- 'cm##re.ca':80
- http://cm##re.ca/1/
- DNS ASK bi#.ly
- DNS ASK pr######eathleticsinc.com
- DNS ASK u.##knik.io
- DNS ASK cm##re.ca
- '%TEMP%\yvetqqyefi.exe'
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding