Техническая информация
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'm5hl' = '%APPDATA%\lur2goj0ud.exe'
- lur2goj0ud.exe
- %APPDATA%\lur2goj0ud.exe
- 'mk###i4kdsz.com':80
- 'ow###rasuek.com':80
- http://mk###i4kdsz.com/132/860.html
- http://ow###rasuek.com/512/238.html
- DNS ASK ko##od.net
- DNS ASK mk###i4kdsz.com
- DNS ASK ow###rasuek.com
- '%APPDATA%\lur2goj0ud.exe'