Техническая информация
- %WINDIR%\tasks\edge.job
- <SYSTEM32>\tasks\edge
- %TEMP%\clifford.dll
- '<SYSTEM32>\notepad.exe'
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 304
- <SYSTEM32>\notepad.exe
- %WINDIR%\syswow64\notepad.exe
- %TEMP%\clifford.dll
- %TEMP%\4030001.jpg
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\aapocclcgogkmnckokdopfmhonfmgoek\edge.exe
- %LOCALAPPDATA%\google\chrome\user data\default\extensions\aapocclcgogkmnckokdopfmhonfmgoek\libssp-0.dll
- %TEMP%\1219085.cvr
- %TEMP%\bitcd5d.tmp
- %TEMP%\bitcd5d.tmp
- %TEMP%\bitcd5d.tmp в %TEMP%\2147770c.png
- 'i.##b.co':443
- 'i.##gur.com':443
- 'i.##b.co':443
- 'i.##gur.com':443
- DNS ASK i.##b.co
- DNS ASK st####.rapidssl.com
- DNS ASK i.##gur.com
- '%LOCALAPPDATA%\google\chrome\user data\default\extensions\aapocclcgogkmnckokdopfmhonfmgoek\edge.exe'
- '%LOCALAPPDATA%\google\chrome\user data\default\extensions\aapocclcgogkmnckokdopfmhonfmgoek\edge.exe' ' (со скрытым окном)
- '<SYSTEM32>\taskeng.exe' {BC7AB471-E9A1-45BC-BB27-FD9C3ECE826F} S-1-5-21-1960123792-2022915161-3775307078-1001:sodobvno\user:Interactive:[1]
- '%WINDIR%\syswow64\notepad.exe'