Техническая информация
- %WINDIR%\microsoft.net\framework64\v4.0.30319\servicemodelreg.exe
- %WINDIR%\syswow64\rmclient.exe
- conout$
- 'bi#####a.duckdns.org':6939
- 'ge###ugin.net':80
- http://ge###ugin.net/json.gp
- 'bi#####a.duckdns.org':6939
- DNS ASK bi#####a.duckdns.org
- DNS ASK ge###ugin.net
- '%WINDIR%\microsoft.net\framework64\v4.0.30319\servicemodelreg.exe'
- '%WINDIR%\syswow64\sc.exe' /stext "%TEMP%\gwhieyyabyy"
- '%WINDIR%\syswow64\sc.exe' /stext "%TEMP%\qymtfrjcpgqpvzw"
- '%WINDIR%\syswow64\sc.exe' /stext "%TEMP%\asrlfbuvloiuyfspnm"