Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] '<SYSTEM32>\winlogon.exe' = '<SYSTEM32>\winlogon.exe:*:enabled:@shell32.dll,-1'
- <SYSTEM32>\winlogon.exe
- 'yw##ae.com':443
- 'ib##pi.com':443
- 'vh##sv.com':443
- 'ml##ui.com':443
- 'vo##wo.com':443
- 'nq##da.com':443
- 'il#.#renz.pl':80
- 'aa##yu.com':443
- 'gz##ae.com':443
- 'tg##zm.com':443
- DNS ASK yw##ae.com
- DNS ASK ib##pi.com
- DNS ASK vh##sv.com
- DNS ASK ml##ui.com
- DNS ASK vo##wo.com
- DNS ASK nq##da.com
- DNS ASK il#.#renz.pl
- DNS ASK aa##yu.com
- DNS ASK gz##ae.com
- DNS ASK tg##zm.com