Техническая информация
- <SYSTEM32>\tasks\firefox default browser agent 47c61e3d359a75ad
- %WINDIR%\microsoft.net\framework\v4.0.30319\applaunch.exe
- e4a4.exe
- %LOCALAPPDATA%\google\chrome\user data\default\cookies
- %LOCALAPPDATA%\google\chrome\user data\default\login data
- %LOCALAPPDATA%\google\chrome\user data\default\web data
- %APPDATA%\opera software\opera stable\login data
- %APPDATA%\jwgrciv
- %TEMP%\c5be.exe
- %TEMP%\e4a4.exe
- %APPDATA%\jwgrciv
- 'fi#####in-host-12.com':80
- 'tr##sfer.sh':443
- 'wo#####ntertainment.com':443
- 'cd#.##scordapp.com':443
- '92.##.105.227':38134
- 'ch##pd.link':80
- '62.##3.112.190':80
- 'pr###ader.net':443
- http://ch##pd.link/CALC1.exe
- http://fi#####in-host-12.com/
- 'tr##sfer.sh':443
- 'wo#####ntertainment.com':443
- 'cd#.##scordapp.com':443
- '92.##.105.227':38134
- 'pr###ader.net':443
- DNS ASK ho#####ta-coin-11.com
- DNS ASK fi#####in-host-12.com
- DNS ASK tr##sfer.sh
- DNS ASK wo#####ntertainment.com
- DNS ASK cd#.##scordapp.com
- DNS ASK ch##pd.link
- DNS ASK pr###ader.net
- '%TEMP%\c5be.exe'
- '%TEMP%\e4a4.exe'
- '%WINDIR%\microsoft.net\framework\v4.0.30319\applaunch.exe'