Техническая информация
- %APPDATA%\microsoft\windows\start menu\programs\startup\vbc.exe
- '' (загружен из сети Интернет)
- 'C:\users\public\vbc.exe'
- %WINDIR%\explorer.exe
- vbc.exe
- C:\users\public\vbc.exe
- C:\users\public\vbc.exe
- '18#.#15.150.75':80
- 'bo#####ntrevival.com':80
- 'ce###onlus.com':80
- 'st####ceremodel.com':80
- 'bo#####shandbrow.com':80
- 'th#####bodybrush.com':80
- 'yi##.info':80
- 'on###ttroi.com':80
- 'yu###ission.com':80
- http://www.th#####ession.computer/mo8t/?2d##################################################################################
- DNS ASK bo#####ntrevival.com
- DNS ASK ce###onlus.com
- DNS ASK ke####ampias.com
- DNS ASK ke####istance.net
- DNS ASK st####ceremodel.com
- DNS ASK bo#####shandbrow.com
- DNS ASK th#####bodybrush.com
- DNS ASK be####byherbs.com
- DNS ASK yi##.info
- DNS ASK ih####estudy.com
- DNS ASK th#####ession.computer
- DNS ASK on###ttroi.com
- DNS ASK ti###cheats.com
- DNS ASK yu###ission.com
- '<SYSTEM32>\cmd.exe' /c Copy "C:\Users\Public\vbc.exe" "%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\vbc.exe"' (со скрытым окном)
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding
- '<SYSTEM32>\cmd.exe' /c Copy "C:\Users\Public\vbc.exe" "%APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\vbc.exe"
- '<SYSTEM32>\dwm.exe'
- '<SYSTEM32>\cmd.exe' del "C:\Users\Public\vbc.exe"