Техническая информация
- %APPDATA%\microsoft\windows\start menu\programs\startup\sysapp.exe
- '' (загружен из сети Интернет)
- 'C:\users\public\vbc.exe'
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' copy-item 'C:\Users\Public\vbc.exe' '%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\Sysapp.exe'
- %WINDIR%\explorer.exe
- vbc.exe
- %WINDIR%\syswow64\autofmt.exe
- C:\users\public\vbc.exe
- '19#.#44.176.246':80
- 'th###ensa.com':80
- 'ni####derpickel.net':80
- 'tr#####cappadocia.com':80
- '22##.xyz':80
- 'th####bour1217.com':80
- 'il####ealstate.com':80
- 'as#####iedchicken.com':80
- 'be####fractor.com':80
- 'ch####llgeyer.com':80
- 'ec####anmalta.com':80
- http://www.vi####arketing.tips/att3/?aB#####################################################################################
- DNS ASK th###ensa.com
- DNS ASK ni####derpickel.net
- DNS ASK pg###gmn.icu
- DNS ASK tr#####cappadocia.com
- DNS ASK 22##.xyz
- DNS ASK th####bour1217.com
- DNS ASK il####ealstate.com
- DNS ASK to###noc.com
- DNS ASK as#####iedchicken.com
- DNS ASK be####fractor.com
- DNS ASK ch####llgeyer.com
- DNS ASK en#####basvuruformu.com
- DNS ASK sp###nter.net
- DNS ASK vi####arketing.tips
- DNS ASK ec####anmalta.com
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding
- '%WINDIR%\syswow64\cmstp.exe'