Техническая информация
- [HKLM\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run] '15HWIoqagL60' = '%APPDATA%\toilet\zlK15E_G0092s7\15HWIoqagL60.exe'
- %APPDATA%\toilet\zlk15e_g0092s7\15hwioqagl60.txt
- %APPDATA%\toilet\zlk15e_g0092s7\15hwioqagl60.exe
- %APPDATA%\toilet\zlk15e_g0092s7\vjsc.dll
- %LOCALAPPDATA%\1fcbfbff000606a6
- %APPDATA%\toilet\zlk15e_g0092s7\key
- '43.#25.47.9':8080
- 'mo#####.map.fastly.net':443
- '43.#25.47.9':12345
- http://43.###.47.9:8080/9x.dll via 43.#25.47.9
- '43.#25.47.9':12345
- DNS ASK mo#####.map.fastly.net
- DNS ASK co##############e-chains.prod.autograph.services.mozaws.net
- '%APPDATA%\toilet\zlk15e_g0092s7\15hwioqagl60.exe'
- '<Полный путь к файлу>' 45063C065A06530675066306740675065A0673067506630674065A0647067606760642066706720667065A065406690667066B066F06680661065A06720669066F066A06630672065A067C066A064D0637063306430659064106360636063F063... (со скрытым окном)