Техническая информация
- %WINDIR%\tasks\hwitwad.job
- <SYSTEM32>\tasks\hwitwad
- %ALLUSERSPROFILE%\sstttpq\hwitwad.exe
- %ALLUSERSPROFILE%\microsoft\crypto\rsa\s-1-5-18\d42cc0c3858a58db2db37658219e6400_8cf7b530-613e-439b-a8c5-ccfc0e745400
- %LOCALAPPDATA%\microsoft\penworkspace\discovercachedata.dat
- '80.#5.84.79':4001
- 'ap#.#pify.org':443
- '12#.31.0.34':9131
- '17#.#5.193.9':443
- '19#.#09.206.212':80
- '86.#9.21.38':80
- '13#.#88.40.189':80
- 'ap#.#pify.org':443
- DNS ASK ap#.#pify.org
- '%ALLUSERSPROFILE%\sstttpq\hwitwad.exe' start