Техническая информация
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'csrcs' = '%TEMP%\csrcs.exe'
- %WINDIR%\syswow64\svchost.exe
- %TEMP%\csrcs.exe
- 'no####-than.co.cc':80
- 'ch####-pastry.co.cc':80
- http://no####-than.co.cc/sV1LHv4WZGvBOSpq1GI9I4N7PnfVYG1xwmB8Kz_3d_3d
- http://ch####-pastry.co.cc/tVoTHfoRPGjFPnJp0GVlIId8ZnTRZzVyxmckKD_3d_3d
- DNS ASK no####-than.co.cc
- DNS ASK ch####-pastry.co.cc
- '%TEMP%\csrcs.exe'
- '%WINDIR%\syswow64\svchost.exe'