Техническая информация
- %TEMP%\ixp000.tmp\comment
- %TEMP%\ixp000.tmp\ride
- %TEMP%\ixp000.tmp\malta.adts
- %TEMP%\ixp000.tmp\cookie
- %TEMP%\ixp000.tmp\trustees
- %TEMP%\ixp000.tmp\remainder.adts
- %TEMP%\ixp000.tmp\spot.adts
- %TEMP%\ixp000.tmp\bend.adts
- %TEMP%\ixp000.tmp\continuing.adts
- %TEMP%\ixp000.tmp\faces.adts
- %TEMP%\ixp000.tmp\626792\accounting.exe
- %TEMP%\ixp000.tmp\626792\k
- %TEMP%\ixp000.tmp\626792\k
- 't.#e':443
- 'tu###ul.cyou':443
- 't.#e':443
- 'tu###ul.cyou':443
- DNS ASK Um#######jxKSs.UmMLbMEQqjxKSs
- DNS ASK t.#e
- DNS ASK tu###ul.cyou
- '%TEMP%\ixp000.tmp\626792\accounting.exe' k
- '<SYSTEM32>\sc.exe' /?alksjdfhjf834827435 (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /v /c Set egHEsWw=cmd & !egHEsWw! < Malta.adts (со скрытым окном)
- '<SYSTEM32>\cmd.exe'
- '<SYSTEM32>\findstr.exe' /V "lift" Ride