Техническая информация
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Kurxeeoqsh' = 'C:\Users\Public\Libraries\hsqoeexruK.url'
- %WINDIR%\syswow64\logagent.exe
- C:\users\public\libraries\kurxeeoqsh.exe
- C:\users\public\libraries\hsqoeexruk.url
- 'en###.org.br':80
- 'mi########updatetool.duckdns.org':49155
- http://en###.org.br/admin/ggdt3gyhdddhjfdhdjjdhdhfr739rfjhf6yrb7yghhdhydyedg/Kurxeeoqshohnuyektoolfcizaqjtot
- 'mi########updatetool.duckdns.org':49155
- DNS ASK en###.org.br
- DNS ASK mi########updatetool.duckdns.org
- '%WINDIR%\syswow64\logagent.exe'