Техническая информация
- <SYSTEM32>\tasks\firefox default browser agent a3c35fd77240dd99
- %WINDIR%\explorer.exe
- icwrgua
- %APPDATA%\icwrgua
- %APPDATA%\icwrgua
- 'ho####ile-host6.com':80
- http://ho####ile-host6.com/
- DNS ASK ho####ile-host6.com
- DNS ASK ho####ost-file8.com
- '%APPDATA%\icwrgua'
- '%APPDATA%\icwrgua' ' (со скрытым окном)
- '<SYSTEM32>\taskeng.exe' {4B50A1D2-384A-4024-B1DD-282165CBFA5F} S-1-5-21-1960123792-2022915161-3775307078-1001:hsnkzslvjl\user:Interactive:[1]