Техническая информация
- <SYSTEM32>\runtimebroker.exe
- Процесс meqswvf.exe, модуль ntdll.dll
- 'qq######7vhj.share.zrok.io':443
- 'oc##.###tg2.amazontrust.com':80
- 'oc##.####ca1.amazontrust.com':80
- 'oc##.###01.amazontrust.com':80
- http://oc##.####ca1.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBRPWaOUU8%2B5VZ5%2Fa9jFTaU9pkK3FAQUhBjMhTTsvAyUlC4IWZzHshBOCggCEwdzEjgLnWaIozse2b%2BczaaODg8%3D
- http://oc##.###01.amazontrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBShdVEFnSEQ0gG5CBtzM48cPMe9XwQUgbgOY4qJEhjl%2Bjs7UJWf5uWQE4UCEAsxNkB2aTS5UqqK8aNeNu8%3D
- 'qq######7vhj.share.zrok.io':443
- DNS ASK qq######7vhj.share.zrok.io
- DNS ASK oc##.###tg2.amazontrust.com
- DNS ASK oc##.####ca1.amazontrust.com
- DNS ASK oc##.###01.amazontrust.com
- '<SYSTEM32>\runtimebroker.exe'