Техническая информация
- %APPDATA%\microsoft\windows\start menu\programs\startup\lilithworker.exe
- 'ip##pi.com':80
- '45.#.148.203':4545
- http://ip##pi.com/line?fi##########
- http://45.#.#48.203:4545/gate/66d26096-3ad2-4574-834e-b128668a847f/getFile?na############################# via 45.#.148.203
- http://45.#.#48.203:4545/gate/66d26096-3ad2-4574-834e-b128668a847f/getCommands via 45.#.148.203
- http://45.#.#48.203:4545/gate/66d26096-3ad2-4574-834e-b128668a847f/registerBot via 45.#.148.203
- DNS ASK ip##pi.com