Техническая информация
- %WINDIR%\tasks\lymmqeui.job
- <SYSTEM32>\tasks\lymmqeui
- %ALLUSERSPROFILE%\microsoft\crypto\rsa\s-1-5-18\d42cc0c3858a58db2db37658219e6400_8cf7b530-613e-439b-a8c5-ccfc0e745400
- %TEMP%\adaa4fbc41\lymmqeui.exe
- 'co##############e-chains.prod.autograph.services.mozaws.net':443
- 'mi#####ft-telemetry.cc':80
- 'xb######metry-defender.cc':80
- 'mo#####.map.fastly.net':443
- http://mi#####ft-telemetry.cc/cvdfnaFJBmC1/index.php
- http://mi#####ft-telemetry.at/cvdfnaFJBmC0/index.php
- http://xb######metry-defender.cc/cvdfnaFJBmC2/index.php
- DNS ASK co##############e-chains.prod.autograph.services.mozaws.net
- DNS ASK mi#####ft-telemetry.at
- DNS ASK mi#####ft-telemetry.cc
- DNS ASK xb######metry-defender.cc
- DNS ASK mo#####.map.fastly.net
- '%TEMP%\adaa4fbc41\lymmqeui.exe'
- '%TEMP%\adaa4fbc41\lymmqeui.exe' (со скрытым окном)