Техническая информация
- <SYSTEM32>\tasks\mytask
- %WINDIR%\syswow64\notepad.exe
- %WINDIR%\syswow64\mylog.log
- %WINDIR%\inf\ups.ini
- %WINDIR%\temp\upsupx3.exe
- '19#.#6.179.85':80
- '66.##5.246.6':80
- 'ms#####.load230713.ru':80
- http://19#.#6.179.85/upsupx3.txt
- http://66.##5.246.6/upsupx3.exe
- http://ms#####.load230713.ru/Mssqlb.bin
- DNS ASK ms#####.load230713.ru
- '%WINDIR%\temp\upsupx3.exe'
- '%WINDIR%\syswow64\notepad.exe'