Техническая информация
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Ad' = '%APPDATA%\ID.exe'
- %APPDATA%\microsoft\windows\start menu\programs\startup\ide.exe
- %APPDATA%\microsoft\windows\start menu\programs\startup\ide.lnk
- %APPDATA%\id.exe
- 'localhost':1789
- '<LOCALNET>.1.175':1789
- 'da#####y1.servebeer.com':1789
- '<LOCALNET>.10.175':1789
- DNS ASK da#####y5.servebeer.com
- DNS ASK da######15.servebeer.com
- DNS ASK da#####y1.servebeer.com
- '%APPDATA%\id.exe'