Техническая информация
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'Discovery Config Cache Image List' = '%APPDATA%\vtfutcph\ieuycao.exe'
- %APPDATA%\vtfutcph\ieuycao.exe
- %APPDATA%\vtfutcph\wkwntpxzglqo.exe
- %APPDATA%\vtfutcph\ieuycao.sjxgw
- %APPDATA%\vtfutcph\ieuycao.exe
- DNS ASK en####hreason.net
- DNS ASK ei####orderly.net
- DNS ASK en####horderly.net
- DNS ASK ei###rvalue.net
- DNS ASK en####hvalue.net
- DNS ASK ex####chance.net
- DNS ASK be####echance.net
- DNS ASK ex####meeting.net
- DNS ASK be####emeeting.net
- '%APPDATA%\vtfutcph\ieuycao.exe'
- '%APPDATA%\vtfutcph\wkwntpxzglqo.exe' "%APPDATA%\vtfutcph\ieuycao.exe"