Техническая информация
- <SYSTEM32>\tasks\firefox default browser agent 38f2b8d72003a4d7
- %APPDATA%\evhrgsb
- %TEMP%\f391.exe
- %APPDATA%\thunderbird\profiles\wjj9aet2.default\cookies.sqlite-shm
- %APPDATA%\evhrgsb
- %APPDATA%\thunderbird\profiles\wjj9aet2.default\cookies.sqlite-shm
- %TEMP%\f391.exe
- 'ho####ile-host6.com':80
- '78.##8.114.119':80
- http://78.##8.114.119/12345.exe
- http://ho####ile-host6.com/
- DNS ASK ho####ile-host6.com
- '%TEMP%\f391.exe'
- '%APPDATA%\evhrgsb'
- '%APPDATA%\evhrgsb' ' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /C choice /C Y /N /D Y /T 0 &Del %TEMP%\F391.exe
- '<SYSTEM32>\choice.exe' /C Y /N /D Y /T 0
- '<SYSTEM32>\taskeng.exe' {0891D903-B68E-483D-9614-542A9E33ABE9} S-1-5-21-1960123792-2022915161-3775307078-1001:fomebduhbt\user:Interactive:[1]