Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run\] 'kkl' = '"%APPDATA%\oos.exe"'
- [<HKLM>\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\] 'kkl' = '"%APPDATA%\oos.exe"'
- '' (загружен из сети Интернет)
- 'C:\users\public\vbc.exe'
- '%ProgramFiles%\microsoft office\office14\winword.exe' /n "%TEMP%\A9R1iipna5_1s09zv4_1ao.tmp\has been verified. However PDF, JPEG, xlsx, .docx"
- oos.exe
- %TEMP%\a9r1iipna5_1s09zv4_1ao.tmp\has been verified. however pdf, jpeg, xlsx, .docx
- C:\users\public\vbc.exe
- %APPDATA%\oos.exe
- %TEMP%\install.vbs
- %ALLUSERSPROFILE%\remcos\logs.dat
- %APPDATA%\oos.exe
- %TEMP%\install.vbs
- '45.##.190.156':80
- 'xp#####z300622.ddns.net':3542
- 'ge###ugin.net':80
- http://45.##.190.156/shpp/document_260.doc
- http://45.##.190.156/260/vbc.exe
- http://ge###ugin.net/json.gp
- 'xp#####z300622.ddns.net':3542
- DNS ASK xp#####z300622.ddns.net
- DNS ASK ge###ugin.net
- '%WINDIR%\syswow64\wscript.exe' "%TEMP%\install.vbs"
- '%APPDATA%\oos.exe'
- '%WINDIR%\syswow64\wscript.exe' "%TEMP%\install.vbs"' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /c "%APPDATA%\oos.exe"' (со скрытым окном)
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding
- '%WINDIR%\syswow64\cmd.exe' /c "%APPDATA%\oos.exe"