Техническая информация
- %APPDATA%\microsoft\windows\start menu\programs\startup\sfgdfgdfd.exe
- '' (загружен из сети Интернет)
- 'C:\users\public\vbc.exe'
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' copy-item 'C:\Users\Public\vbc.exe' '%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\Sfgdfgdfd.exe'
- %WINDIR%\explorer.exe
- vbc.exe
- C:\users\public\vbc.exe
- '19#.#44.176.246':80
- 'ja#####ojeekspertiz.com':80
- 'sp###aplus.com':80
- 'ch####llgeyer.com':80
- 'mo#####eloansbyjeff.com':80
- 'tr#####cappadocia.com':80
- http://www.as#####iedchicken.com/att3/?mt##########################################################################################
- http://www.oa######efundservices.com/att3/?mt##########################################################################################
- DNS ASK ja#####ojeekspertiz.com
- DNS ASK to###only8.info
- DNS ASK df###ushds.xyz
- DNS ASK sp###aplus.com
- DNS ASK as#####iedchicken.com
- DNS ASK ch####llgeyer.com
- DNS ASK mo#####eloansbyjeff.com
- DNS ASK oa######efundservices.com
- DNS ASK tr#####cappadocia.com
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding
- '%WINDIR%\syswow64\control.exe'