Техническая информация
- %TEMP%\20230917t001523_506.exe
- %TEMP%\20230917t001556_289.exe
- %TEMP%\20230917t001622_073.exe
- '20##########523_506.ltiapmyzmjxrvrts.info':80
- '20##########556_289.ltiapmyzmjxrvrts.info':80
- '20##########622_073.ltiapmyzmjxrvrts.info':80
- '20##########651_733.ltiapmyzmjxrvrts.info':80
- http://20##########523_506.ltiapmyzmjxrvrts.info/v4/20230917T001523_506.exe
- http://20##########556_289.ltiapmyzmjxrvrts.info/v4/20230917T001556_289.exe
- http://20##########622_073.ltiapmyzmjxrvrts.info/v4/20230917T001622_073.exe
- http://20##########651_733.ltiapmyzmjxrvrts.info/v4/20230917T001651_733.exe
- DNS ASK 20##########523_506.ltiapmyzmjxrvrts.info
- DNS ASK 20##########556_289.ltiapmyzmjxrvrts.info
- DNS ASK 20##########622_073.ltiapmyzmjxrvrts.info
- DNS ASK 20##########651_733.ltiapmyzmjxrvrts.info
- '%TEMP%\20230917t001523_506.exe'
- '%TEMP%\20230917t001556_289.exe'
- '%TEMP%\20230917t001622_073.exe'
- '<SYSTEM32>\cmd.exe' /c %TEMP%\20230917T001523_506.exe
- '<SYSTEM32>\cmd.exe' /c %TEMP%\20230917T001556_289.exe
- '<SYSTEM32>\cmd.exe' /c %TEMP%\20230917T001622_073.exe
- '<SYSTEM32>\cmd.exe' /c %TEMP%\20230917T001651_733.exe