Техническая информация
- %APPDATA%\microsoft\windows\start menu\programs\startup\hezron.vbs
- %WINDIR%\syswow64\svchost.exe
- [HKCU\Software\FTPWare\COREFTP\Sites\]
- [HKCU\Software\Martin Prikryl\WinSCP 2\Sessions\]
- %LOCALAPPDATA%\google\chrome\user data\default\web data
- %LOCALAPPDATA%\google\chrome\user data\default\login data
- %APPDATA%\opera software\opera stable\login data
- %LOCALAPPDATA%\microsoft\edge\user data\default\login data
- %LOCALAPPDATA%\microsoft\edge\user data\default\web data
- %TEMP%\aut4002.tmp
- %TEMP%\atule
- %TEMP%\aut4236.tmp
- %TEMP%\sancha
- %LOCALAPPDATA%\mazateco\hezron.exe
- %TEMP%\aut462c.tmp
- %TEMP%\aut4821.tmp
- %APPDATA%\microsoft\windows\templates\udrlpop-user\logindata
- %APPDATA%\microsoft\windows\templates\udrlpop-user\webdata
- %TEMP%\aut4002.tmp
- %TEMP%\aut4236.tmp
- %TEMP%\aut462c.tmp
- %TEMP%\aut4821.tmp
- 'mo#####.map.fastly.net':443
- 'co##############e-chains.prod.autograph.services.mozaws.net':443
- DNS ASK mo#####.map.fastly.net
- DNS ASK co##############e-chains.prod.autograph.services.mozaws.net
- '%LOCALAPPDATA%\mazateco\hezron.exe'
- '%WINDIR%\syswow64\svchost.exe'