Техническая информация
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'RegSvcs' = '%APPDATA%\RegSvcs.exe'
- %APPDATA%\microsoft\windows\start menu\programs\startup\sancerre.vbs
- %WINDIR%\microsoft.net\framework\v4.0.30319\regsvcs.exe
- %TEMP%\autfc3e.tmp
- %TEMP%\croc
- %LOCALAPPDATA%\complacence\sancerre.exe
- %TEMP%\aut90f.tmp
- %APPDATA%\regsvcs.exe
- %TEMP%\6996c6c4a7341737be2c5bc485ae54f9\gecko_cookies_tlhjfklgy_2026-01-26_16.51.59.json
- %TEMP%\6996c6c4a7341737be2c5bc485ae54f9\tlhjfklgy_20260126_165226.png
- %TEMP%\autfc3e.tmp
- %TEMP%\aut90f.tmp
- %TEMP%\6996c6c4a7341737be2c5bc485ae54f9\gecko_cookies_tlhjfklgy_2026-01-26_16.51.59.json
- 'ic###azip.com':80
- 'ma##.###kirantekstil.com':587
- http://ic###azip.com/
- DNS ASK ic###azip.com
- DNS ASK ma##.###kirantekstil.com
- '%LOCALAPPDATA%\complacence\sancerre.exe'
- '%WINDIR%\microsoft.net\framework\v4.0.30319\regsvcs.exe'