Техническая информация
- <SYSTEM32>\tasks\firefox default browser agent 7a24e06591c13483
- %WINDIR%\explorer.exe
- %APPDATA%\hrfsrhf
- %APPDATA%\hrfsrhf
- 'po###ulit.org':80
- 'hu###lior.net':80
- 'bu###u55t.net':80
- 'so###tlic4.net':80
- 'no####sa5org.org':80
- 'to###olihul.net':80
- 'so####ka51hub.net':80
- 'hu###ui3.net':80
- 'bu###uka1.net':80
- 'go####paster.org':80
- http://po###ulit.org/
- http://hu###lior.net/
- http://bu###u55t.net/
- http://so###tlic4.net/
- http://no####sa5org.org/
- http://so####ka51hub.net/
- http://bu###uka1.net/
- http://go####paster.org/
- DNS ASK po###ulit.org
- DNS ASK hu###lior.net
- DNS ASK bu###u55t.net
- DNS ASK so###tlic4.net
- DNS ASK no####sa5org.org
- DNS ASK nu###jnuli.org
- DNS ASK to###olihul.net
- DNS ASK so####ka51hub.net
- DNS ASK hu###ui3.net
- DNS ASK bu###uka1.net
- DNS ASK go####paster.org
- '%APPDATA%\hrfsrhf'
- '%APPDATA%\hrfsrhf' ' (со скрытым окном)
- '<SYSTEM32>\taskeng.exe' {F8076BE3-F53D-4333-AC2A-444EBF3BAD8C} S-1-5-21-1238866942-1249195528-555854008-1000:dozyuxlfh\user:Interactive:[1]