Техническая информация
- %APPDATA%\microsoft\windows\start menu\programs\startup\sulfhydrate.vbs
- %WINDIR%\syswow64\svchost.exe
- %TEMP%\auta469.tmp
- %TEMP%\oxmanship
- %LOCALAPPDATA%\graff\sulfhydrate.exe
- %TEMP%\autafce.tmp
- %TEMP%\auta469.tmp
- %TEMP%\autafce.tmp
- '10#.#3.87.190':5817
- 'ge###ugin.net':80
- http://ge###ugin.net/json.gp
- '10#.#3.87.190':5817
- DNS ASK ge###ugin.net
- '%LOCALAPPDATA%\graff\sulfhydrate.exe'
- '%WINDIR%\syswow64\svchost.exe'