Техническая информация
- '' (загружен из сети Интернет)
- 'C:\users\public\vbc.exe'
- %WINDIR%\explorer.exe
- vbc.exe
- C:\users\public\vbc.exe
- %TEMP%\vbc.exe
- %TEMP%\vbc.exe
- 'po###.ddnsking.com':80
- '20####dsledge.com':80
- 'sw###missy.net':80
- 'om#####ainsurance.com':80
- 'ri#####ftstudios.com':80
- 'pa####riabooks.com':80
- 'il######tegenuinehope.xyz':80
- 'xu##h.com':80
- DNS ASK po###.ddnsking.com
- DNS ASK dn#.google
- DNS ASK 20####dsledge.com
- DNS ASK sw###missy.net
- DNS ASK om#####ainsurance.com
- DNS ASK ri#####ftstudios.com
- DNS ASK ib#####tlivewdmall.com
- DNS ASK th#####sofisrael.com
- DNS ASK ho#####carservices.com
- DNS ASK pa####riabooks.com
- DNS ASK il######tegenuinehope.xyz
- DNS ASK 12##0xk.com
- DNS ASK xu##h.com
- '%TEMP%\vbc.exe'
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' Test-Connection 8.8.8.8' (со скрытым окном)
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' Test-Connection 8.8.8.8
- '%WINDIR%\syswow64\wlanext.exe'
- '%WINDIR%\syswow64\cmd.exe' del "%TEMP%\vbc.exe"