Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'Shared' = '<SYSTEM32>\sms.exe'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] 'EnableFirewall' = '00000000'
- %HOMEPATH%\Local Settings\Temporary Internet Files\Content.IE5\KHMHGZ4F\file_upload[1].htm
- %TEMP%\20136271825_CRNJEUFU.jsw
- %TEMP%\log.record
- %TEMP%\20136271825_CRNJEUFU.jsw
- %TEMP%\log.record
- 'im###.#isecart.co.kr':80
- DNS ASK im###.#isecart.co.kr