Техническая информация
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'lupyienw' = '%APPDATA%\hqaueaj\soxhdmirbwgp.exe "%TEMP%\duksfkef.exe" %HOMEPATH%\AppData\Loca�'
- duksfkef.exe
- %TEMP%\nsw62f7.tmp
- %TEMP%\fbuwoilncge.c
- %TEMP%\yyyvapnrtmi.u
- %TEMP%\duksfkef.exe
- %APPDATA%\hqaueaj\soxhdmirbwgp.exe
- DNS ASK bl#####ots7.duckdns.org
- '%TEMP%\duksfkef.exe' %TEMP%\yyyvapnrtmi.u
- '%TEMP%\duksfkef.exe'