Техническая информация
- <SYSTEM32>\tasks\firefox default browser agent 0709966083c5c228
- %WINDIR%\explorer.exe
- urchbws
- %APPDATA%\urchbws
- %TEMP%\6316.exe
- %TEMP%\8d10.exe
- %APPDATA%\urchbws
- 'ho####ile-host6.com':80
- 'da#####st-file-16.com':80
- 'rg##i.top':80
- 'an###iles.com':443
- 'dl.###oadgram.me':443
- http://rg##i.top/dl/buildz.exe
- http://da#####st-file-16.com/downloads/toolspab1.exe
- http://ho####ile-host6.com/
- 'an###iles.com':443
- 'dl.###oadgram.me':443
- DNS ASK ho####ile-host6.com
- DNS ASK da#####st-file-16.com
- DNS ASK rg##i.top
- DNS ASK an###iles.com
- DNS ASK dl.###oadgram.me
- DNS ASK microsoft.com
- '%TEMP%\6316.exe'
- '%APPDATA%\urchbws'
- '%TEMP%\8d10.exe'
- '%APPDATA%\urchbws' ' (со скрытым окном)
- '<SYSTEM32>\taskeng.exe' {8830F366-F30C-490A-BC67-24FFDC9B7546} S-1-5-21-1960123792-2022915161-3775307078-1001:obdqbtagqvj\user:Interactive:[1]