Техническая информация
- %TEMP%\20230912t032355_388.exe
- %TEMP%\20230912t032417_194.exe
- %TEMP%\20230912t032447_428.exe
- '20##########355_388.ltiapmyzmjxrvrts.info':80
- '20##########417_194.ltiapmyzmjxrvrts.info':80
- '20##########447_428.ltiapmyzmjxrvrts.info':80
- '20##########512_560.ltiapmyzmjxrvrts.info':80
- http://20##########355_388.ltiapmyzmjxrvrts.info/v4/20230912T032355_388.exe
- http://20##########417_194.ltiapmyzmjxrvrts.info/v4/20230912T032417_194.exe
- http://20##########447_428.ltiapmyzmjxrvrts.info/v4/20230912T032447_428.exe
- http://20##########512_560.ltiapmyzmjxrvrts.info/v4/20230912T032512_560.exe
- DNS ASK 20##########355_388.ltiapmyzmjxrvrts.info
- DNS ASK 20##########417_194.ltiapmyzmjxrvrts.info
- DNS ASK 20##########447_428.ltiapmyzmjxrvrts.info
- DNS ASK 20##########512_560.ltiapmyzmjxrvrts.info
- '%TEMP%\20230912t032355_388.exe'
- '%TEMP%\20230912t032417_194.exe'
- '%TEMP%\20230912t032447_428.exe'
- '<SYSTEM32>\cmd.exe' /c %TEMP%\20230912T032355_388.exe
- '<SYSTEM32>\cmd.exe' /c %TEMP%\20230912T032417_194.exe
- '<SYSTEM32>\cmd.exe' /c %TEMP%\20230912T032447_428.exe
- '<SYSTEM32>\cmd.exe' /c %TEMP%\20230912T032512_560.exe