Техническая информация
- %TEMP%\20230911t220543_384.exe
- %TEMP%\20230911t220612_430.exe
- %TEMP%\20230911t220645_983.exe
- '20##########543_384.ltiapmyzmjxrvrts.info':80
- '20##########612_430.ltiapmyzmjxrvrts.info':80
- '20##########645_983.ltiapmyzmjxrvrts.info':80
- '20##########717_116.ltiapmyzmjxrvrts.info':80
- http://20##########543_384.ltiapmyzmjxrvrts.info/v4/20230911T220543_384.exe
- http://20##########612_430.ltiapmyzmjxrvrts.info/v4/20230911T220612_430.exe
- http://20##########645_983.ltiapmyzmjxrvrts.info/v4/20230911T220645_983.exe
- http://20##########717_116.ltiapmyzmjxrvrts.info/v4/20230911T220717_116.exe
- DNS ASK 20##########543_384.ltiapmyzmjxrvrts.info
- DNS ASK 20##########612_430.ltiapmyzmjxrvrts.info
- DNS ASK 20##########645_983.ltiapmyzmjxrvrts.info
- DNS ASK 20##########717_116.ltiapmyzmjxrvrts.info
- '%TEMP%\20230911t220543_384.exe'
- '%TEMP%\20230911t220612_430.exe'
- '%TEMP%\20230911t220645_983.exe'
- '<SYSTEM32>\cmd.exe' /c %TEMP%\20230911T220543_384.exe
- '<SYSTEM32>\cmd.exe' /c %TEMP%\20230911T220612_430.exe
- '<SYSTEM32>\cmd.exe' /c %TEMP%\20230911T220645_983.exe