Техническая информация
- %WINDIR%\syswow64\rmclient.exe
- %LOCALAPPDATA%\microsoft\vault\userprofileroaming\latest.dat
- 'ge##bre.com':443
- 'x1.#.lencr.org':80
- 'e6.#.lencr.org':80
- 'uw#w.io':443
- '10#.#75.246.22':80
- http://e6.#.lencr.org/118.crl
- http://10#.#75.246.22/466/clearpicture________00995868689494859699969966556.PHP
- 'ge##bre.com':443
- 'uw#w.io':443
- DNS ASK ge##bre.com
- DNS ASK x1.#.lencr.org
- DNS ASK e6.#.lencr.org
- DNS ASK uw#w.io
- DNS ASK lo###sta.com
- DNS ASK ap#.#pify.org
- DNS ASK ap#.#indip.net