Техническая информация
- <SYSTEM32>\tasks\firefox default browser agent 1de8dc994fefcbc2
- <SYSTEM32>\tasks\jiqqx
- %WINDIR%\syswow64\explorer.exe
- %WINDIR%\explorer.exe
- iexplore.exe
- Процесс iexplore.exe, модуль wininet.dll
- Процесс firefox.exe, модуль nss3.dll
- %APPDATA%\ucrrrwd
- %APPDATA%\buviutj
- %TEMP%\561b.exe
- %LOCALAPPDATA%\sirmqqg\jiqqx.exe
- %APPDATA%\ucrrrwd
- %APPDATA%\buviutj
- 'ko####olitizm.org':80
- 'gi##ub.com':443
- 'dr##box.com':443
- 'cd#####.anonfiles.com':443
- 'tr##sfer.sh':443
- 'al###ahia.cl':443
- 'si##ky.net':443
- '10#.#22.188.59':80
- 'al##is.com':443
- http://10#.#22.188.59/put.exe
- http://ko####olitizm.org/
- 'gi##ub.com':443
- 'dr##box.com':443
- 'cd#####.anonfiles.com':443
- 'tr##sfer.sh':443
- 'al###ahia.cl':443
- 'si##ky.net':443
- 'al##is.com':443
- DNS ASK ko####olitizm.org
- DNS ASK gi##ub.com
- DNS ASK dr##box.com
- DNS ASK cd#####.anonfiles.com
- DNS ASK tr##sfer.sh
- DNS ASK al###ahia.cl
- DNS ASK si##ky.net
- DNS ASK al##is.com
- '%TEMP%\561b.exe'
- '%WINDIR%\syswow64\explorer.exe'
- '%WINDIR%\explorer.exe'