Техническая информация
- <SYSTEM32>\tasks\firefox default browser agent 8c3ecc0449f602d3
- %WINDIR%\explorer.exe
- %APPDATA%\ewvarit
- %APPDATA%\ewvarit
- 'fu###ujjul.net':80
- 'st####stitibo.org':80
- 'li####tiyyyul.net':80
- 'gu####na49org.org':80
- 'st###nuytyt.org':80
- 'yo####umenia5.org':80
- http://fu###ujjul.net/
- http://st####stitibo.org/
- http://li####tiyyyul.net/
- http://gu####na49org.org/
- http://st###nuytyt.org/
- http://yo####umenia5.org/
- DNS ASK fu###ujjul.net
- DNS ASK st####stitibo.org
- DNS ASK li####tiyyyul.net
- DNS ASK bu####tu44org.org
- DNS ASK nv###kuluir.net
- DNS ASK gu####na49org.org
- DNS ASK hu####dulinu.net
- DNS ASK st###nuytyt.org
- DNS ASK nu###tnulo.me
- DNS ASK yo####umenia5.org
- DNS ASK gu####iimnstra.net
- '%APPDATA%\ewvarit'
- '%APPDATA%\ewvarit' ' (со скрытым окном)
- '<SYSTEM32>\taskeng.exe' {336494B8-37DB-4F15-8D97-8ACE09446DB1} S-1-5-21-1960123792-2022915161-3775307078-1001:pdlriwig\user:Interactive:[1]