Техническая информация
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Nctngmus' = 'C:\Users\Public\Libraries\sumgntcN.url'
- %WINDIR%\syswow64\iexpress.exe
- C:\users\public\libraries\nctngmus
- C:\users\public\libraries\nctngmus.exe
- C:\users\public\libraries\sumgntcn.url
- 'bi###otec.org':80
- http://bi###otec.org/beliversimaginationdisplaylightiningdoorsrooftopbarssoccialengineeringadministrazonematersarrisingdomschooltechnicianmattersmomomo/Nctngmuszfw
- DNS ASK bi###otec.org
- '%WINDIR%\syswow64\iexpress.exe' ' (со скрытым окном)
- '%WINDIR%\syswow64\iexpress.exe'