Техническая информация
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] 'd060017275ac86fe62287dd0c625a723' = '"%APPDATA%\SynScanner.exe" ..'
- [HKLM\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] 'd060017275ac86fe62287dd0c625a723' = '"%APPDATA%\SynScanner.exe" ..'
- %APPDATA%\microsoft\windows\start menu\programs\startup\d060017275ac86fe62287dd0c625a723.exe
- '%WINDIR%\syswow64\netsh.exe' firewall add allowedprogram "%APPDATA%\SynScanner.exe" "SynScanner.exe" ENABLE
- ClassName: 'OLLYDBG', WindowName: ''
- %ALLUSERSPROFILE%\syndemoscanner.exe
- %APPDATA%\synscanner.exe
- %ALLUSERSPROFILE%\syndemoscanner.exe
- '4.###.ngrok.io':13822
- DNS ASK 4.###.ngrok.io
- '%ALLUSERSPROFILE%\syndemoscanner.exe'
- '%APPDATA%\synscanner.exe'
- '%WINDIR%\syswow64\netsh.exe' firewall add allowedprogram "%APPDATA%\SynScanner.exe" "SynScanner.exe" ENABLE (со скрытым окном)