Техническая информация
- [HKLM\SYSTEM\CurrentControlSet\Services\hola_update_svc] 'Start' = '00000002'
- [HKLM\SYSTEM\CurrentControlSet\Services\hola_update_svc] 'ImagePath' = '"%ProgramFiles%\Hola\app\updater64.exe"'
- 'hola_update_svc' %ProgramFiles%\Holapp�pdater64.exe
- 'hola_update_svc' %ProgramFiles%\Hola\app\updater64.exe
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoProfile -NonInteractive -ExecutionPolicy Bypass -Command "Add-MpPreference -ExclusionPath '%ProgramFiles%\Hola\app' -ErrorAction SilentlyContinue"
- %ProgramFiles%\hola\app\updater64.exe
- '18#.#41.219.55':9000
- 'et#####m.blinklabs.xyz':443
- 'x1.#.lencr.org':80
- '18#.#41.218.111':8443
- http://18#.##1.219.55:9000/peer.exe via 18#.#41.219.55
- http://x1.#.lencr.org/
- 'et#####m.blinklabs.xyz':443
- '18#.#41.218.111':8443
- DNS ASK et#####m.blinklabs.xyz
- DNS ASK x1.#.lencr.org
- '%ProgramFiles%\hola\app\updater64.exe'
- '<SYSTEM32>\sc.exe' query hola_update_svc