Техническая информация
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'cvchost' = '%LOCALAPPDATA%\cvchost.exe'
- %WINDIR%\microsoft.net\framework\v4.0.30319\installutil.exe
- %LOCALAPPDATA%\cvchost.exe
- %WINDIR%\softwaredistribution\sls\9482f4b4-e343-43b6-b170-9a65bc822c77\sls.cab
- %WINDIR%\softwaredistribution\sls\9482f4b4-e343-43b6-b170-9a65bc822c77\tmpd419.tmp
- %WINDIR%\softwaredistribution\sls\855e8a7c-ecb4-4ca3-b045-1dfa50104289\sls.cab
- %WINDIR%\softwaredistribution\sls\855e8a7c-ecb4-4ca3-b045-1dfa50104289\tmpdb8c.tmp
- %WINDIR%\softwaredistribution\sls\8b24b027-1dee-babb-9a95-3517dfb9c552\sls.cab
- %WINDIR%\softwaredistribution\sls\8b24b027-1dee-babb-9a95-3517dfb9c552\tmpe3da.tmp
- '19#.#33.203.37':80
- 'th####kwwqlm.shop':443
- 'st####ommunity.com':443
- 'se####-esenin.com':443
- http://19#.#33.203.37/cook/Eduxkwamadk.pdf
- 'th####kwwqlm.shop':443
- 'st####ommunity.com':443
- 'se####-esenin.com':443
- DNS ASK th####kwwqlm.shop
- DNS ASK settings-win.data.microsoft.com
- DNS ASK lo####dblsoqp.shop
- DNS ASK tr####iwnqo.shop
- DNS ASK co####qpwqm.shop
- DNS ASK ev####twoqm.shop
- DNS ASK mi####croqwp.shop
- DNS ASK st####chheiqwo.shop
- DNS ASK st####reewntnq.shop
- DNS ASK ca####clasiqwp.shop
- DNS ASK st####ommunity.com
- DNS ASK se####-esenin.com
- '%WINDIR%\microsoft.net\framework\v4.0.30319\installutil.exe'