Техническая информация
- <SYSTEM32>\tasks\firefox default browser agent d976e07c5b0da4cb
- %WINDIR%\explorer.exe
- f9d9.exe
- %APPDATA%\idsfssw
- %TEMP%\f0c4.bat
- %TEMP%\f9d9.exe
- %APPDATA%\idsfssw
- 'ho####ile-host6.com':80
- 're###kt5569.com':80
- 'tr##sfer.sh':443
- 'fi##bin.net':443
- 'fg###fgfg.site':443
- 'tm###les.org':443
- http://re###kt5569.com/downloads/toolspub2.exe
- http://ho####ile-host6.com/
- 'tr##sfer.sh':443
- 'fi##bin.net':443
- 'fg###fgfg.site':443
- 'tm###les.org':443
- DNS ASK ho####ile-host6.com
- DNS ASK re###kt5569.com
- DNS ASK tr##sfer.sh
- DNS ASK fi##bin.net
- DNS ASK fg###fgfg.site
- DNS ASK tm###les.org
- '%TEMP%\f9d9.exe'
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\F0C4.bat" "' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\F0C4.bat" "
- '<SYSTEM32>\reg.exe' add "HKEY_CURRENT_USER\Software\clicker\key" /v primary /t REG_DWORD /d 1