Техническая информация
- %TEMP%\20230913t041137_102.exe
- %TEMP%\20230913t041203_875.exe
- %TEMP%\20230913t041230_642.exe
- %TEMP%\20230913t041300_622.exe
- '20##########137_102.ltiapmyzmjxrvrts.info':80
- '20##########203_875.ltiapmyzmjxrvrts.info':80
- '20##########230_642.ltiapmyzmjxrvrts.info':80
- '20##########300_622.ltiapmyzmjxrvrts.info':80
- http://20##########137_102.ltiapmyzmjxrvrts.info/v4/20230913T041137_102.exe
- http://20##########203_875.ltiapmyzmjxrvrts.info/v4/20230913T041203_875.exe
- http://20##########230_642.ltiapmyzmjxrvrts.info/v4/20230913T041230_642.exe
- http://20##########300_622.ltiapmyzmjxrvrts.info/v4/20230913T041300_622.exe
- DNS ASK 20##########137_102.ltiapmyzmjxrvrts.info
- DNS ASK 20##########203_875.ltiapmyzmjxrvrts.info
- DNS ASK 20##########230_642.ltiapmyzmjxrvrts.info
- DNS ASK 20##########300_622.ltiapmyzmjxrvrts.info
- '%TEMP%\20230913t041137_102.exe'
- '%TEMP%\20230913t041203_875.exe'
- '%TEMP%\20230913t041230_642.exe'
- '%TEMP%\20230913t041300_622.exe'
- '<SYSTEM32>\cmd.exe' /c %TEMP%\20230913T041137_102.exe
- '<SYSTEM32>\cmd.exe' /c %TEMP%\20230913T041203_875.exe
- '<SYSTEM32>\cmd.exe' /c %TEMP%\20230913T041230_642.exe
- '<SYSTEM32>\cmd.exe' /c %TEMP%\20230913T041300_622.exe
- '<SYSTEM32>\cmd.exe' /c %TEMP%\20230913T041329_202.exe