Техническая информация
- %APPDATA%\microsoft\windows\start menu\programs\startup\zaim.js
- '<SYSTEM32>\wscript.exe' C:\Users\Public\zaim.js
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1472
- C:\users\public\zaim.js
- %TEMP%\1126218.cvr
- 'as#####portglass.shop':80
- 'bl##ger.com':443
- 're#####es.blogblog.com':443
- 'oc##.#tartssl.com':80
- 'oc##.thawte.com':80
- http://www.as#####portglass.shop/p/50.html
- http://www.as#####portglass.shop/js/cookienotice.js
- http://oc##.#tartssl.com/sub/class2/code/ca/MEMwQTA%2FMD0wOzAJBgUrDgMCGgUABBQSOgrhRCSnWfKxoWTjWxhk8hga9AQU0E4PQJlsuEsZbzsouODjiAc0qrcCAhAV
- http://oc##.thawte.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQwF4prw9S7mCbCEHD%2Fyl6nWPkczAQUe1tFz6%2FOy3r9MZIaarbzRutXSFACEEeXTXhzpbyrDS%2BzcBkvzl4%3D
- 'bl##ger.com':443
- DNS ASK as#####portglass.shop
- DNS ASK bl##ger.com
- DNS ASK re#####es.blogblog.com
- DNS ASK st####.rapidssl.com
- DNS ASK oc##.#tartssl.com
- DNS ASK oc##.thawte.com
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebCheckMonitor' WindowName: ''
- '<SYSTEM32>\wscript.exe' C:\Users\Public\zaim.js' (со скрытым окном)
- '<SYSTEM32>\mshta.exe' http://www.as#####portglass.shop/p/50.html' (со скрытым окном)
- '<SYSTEM32>\mshta.exe' http://www.as#####portglass.shop/p/50.html