Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'Windows Defender Updater' = '%TEMP%\update_221001.exe / start'
- '' (загружен из сети Интернет)
- 'C:\users\public\vbc.exe'
- vbc.exe
- %LOCALAPPDATA%\google\chrome\user data\default\login data
- %APPDATA%\opera software\opera stable\login data
- %LOCALAPPDATA%\google\chrome\user data\default\web data
- C:\users\public\vbc.exe
- %TEMP%\newtonsoft.json.dll
- %WINDIR%\syswow64\newtonsoft.json.dll
- %TEMP%\nl_178bf1bf000306f2\prosesslist.txt
- %TEMP%\nl_178bf1bf000306f2\programlist.txt
- %TEMP%\nl_178bf1bf000306f2\screenshot.png
- %TEMP%\nl_178bf1bf000306f2\info.txt
- %TEMP%\zip.exe
- %TEMP%\nl_178bf1bf000306f2.zip
- %TEMP%\zip.exe
- C:\users\public\vbc.exe в %TEMP%\update_221001.exe
- '19#.#10.240.7':80
- 'ip##pi.com':80
- 'ha###unesi.info':80
- http://19#.#10.240.7/pdf/day.exe
- http://ip##pi.com/json/
- http://ha###unesi.info/webpanel//gate.php?hw#####################
- http://ha###unesi.info/webpanel//task.php?hw#####################
- DNS ASK ip##pi.com
- DNS ASK ha###unesi.info
- '%TEMP%\zip.exe'
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding