Техническая информация
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Éù¿¨Çý¶¯' = 'C:\Users\Public\Downloads\Fencenls\rsqahr\Agghosts.exe'
- C:\users\public\downloads\misnobi\rsqahr\a.7z
- C:\users\public\downloads\fencenls\rsqahr\server.log
- C:\users\public\downloads\fencenls\rsqahr\agghosts.exe
- C:\users\public\downloads\fencenls\rsqahr\exceptcatch.dll
- C:\users\public\downloads\fencenls\rsqahr\msvcp140.dll
- C:\users\public\downloads\fencenls\rsqahr\vcruntime140.dll
- <Текущая директория>\tem.vbs
- <Текущая директория>\tem.vbs
- <Текущая директория>\tem.vbs
- '69.##6.85.114':8090
- DNS ASK ba##u.com
- 'C:\users\public\downloads\fencenls\rsqahr\agghosts.exe'
- '%WINDIR%\syswow64\wscript.exe' "<Текущая директория>\tem.vbs"