Техническая информация
- %TEMP%\20230912t001603_089.exe
- '20##########603_089.ltiapmyzmjxrvrts.info':80
- '20##########627_485.ltiapmyzmjxrvrts.info':80
- http://20##########603_089.ltiapmyzmjxrvrts.info/v4/20230912T001603_089.exe
- http://20##########627_485.ltiapmyzmjxrvrts.info/v4/20230912T001627_485.exe
- DNS ASK 20##########603_089.ltiapmyzmjxrvrts.info
- DNS ASK 20##########627_485.ltiapmyzmjxrvrts.info
- '%TEMP%\20230912t001603_089.exe'
- '<SYSTEM32>\cmd.exe' /c %TEMP%\20230912T001603_089.exe
- '<SYSTEM32>\cmd.exe' /c %TEMP%\20230912T001627_485.exe