Техническая информация
- [<HKLM>\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] '2N00SWAXF7885INX27' = '%ALLUSERSPROFILE%\036Y3B22O40R6WD4FDH\2N00SWAXF7885INX27.exe'
- %TEMP%\e_n60005\krnln.fnr
- %ALLUSERSPROFILE%\036y3b22o40r6wd4fdh\2n00swaxf7885inx27.exe
- %ALLUSERSPROFILE%\036y3b22o40r6wd4fdh\2n00swaxf7885inx27.data
- %ALLUSERSPROFILE%\036y3b22o40r6wd4fdh\msedgeupdate.dll
- %LOCALAPPDATA%\178bfbff000306e4
- %ALLUSERSPROFILE%\036y3b22o40r6wd4fdh\key
- %TEMP%\gn85l3x6w7\24cdy9t3jk2cd2v1.data
- %TEMP%\gn85l3x6w7\msedgeupdate.dll
- %TEMP%\gn85l3x6w7\24cdy9t3jk2cd2v1.exe
- %TEMP%\gn85l3x6w7\key
- %TEMP%\gn85l3x6w7\r2568.exe
- %TEMP%\gn85l3x6w7\r2568.data
- %ALLUSERSPROFILE%\036y3b22o40r6wd4fdh\key
- %TEMP%\gn85l3x6w7\key
- %TEMP%\gn85l3x6w7\key
- 'localhost':8080
- '18#.#2.180.170':8080
- 'localhost':12345
- '18#.#2.180.170':12345
- http://18#.##.180.170:8080/6X/client.dll via 18#.#2.180.170
- '18#.#2.180.170':12345
- '%ALLUSERSPROFILE%\036y3b22o40r6wd4fdh\2n00swaxf7885inx27.exe'
- '%TEMP%\gn85l3x6w7\24cdy9t3jk2cd2v1.exe'
- '%TEMP%\gn85l3x6w7\r2568.exe'