Техническая информация
- <SYSTEM32>\tasks\firefox default browser agent fab49061aa3df76a
- %WINDIR%\explorer.exe
- erstuga
- %APPDATA%\erstuga
- %TEMP%\92d9.exe
- %APPDATA%\thunderbird\profiles\wjj9aet2.default\cookies.sqlite-shm
- %APPDATA%\erstuga
- %APPDATA%\thunderbird\profiles\wjj9aet2.default\cookies.sqlite-shm
- %TEMP%\92d9.exe
- 'ho####ile-host6.com':80
- 'dl.###oadgram.me':443
- 'cd#####.anonfiles.com':443
- 'ip###ger.org':443
- 'bi###cket.org':443
- http://ho####ile-host6.com/
- 'dl.###oadgram.me':443
- 'cd#####.anonfiles.com':443
- 'ip###ger.org':443
- 'bi###cket.org':443
- DNS ASK ho####ile-host6.com
- DNS ASK dl.###oadgram.me
- DNS ASK microsoft.com
- DNS ASK cd#####.anonfiles.com
- DNS ASK ip###ger.org
- DNS ASK bi###cket.org
- '%APPDATA%\erstuga'
- '%TEMP%\92d9.exe'
- '%APPDATA%\erstuga' ' (со скрытым окном)
- '<SYSTEM32>\taskeng.exe' {1BCF680E-595D-4520-9F75-9FABE388600B} S-1-5-21-1960123792-2022915161-3775307078-1001:xbrsnqleuzz\user:Interactive:[1]
- '<SYSTEM32>\cmd.exe' /C choice /C Y /N /D Y /T 0 &Del %TEMP%\92D9.exe
- '<SYSTEM32>\choice.exe' /C Y /N /D Y /T 0