Техническая информация
- [HKCU\Software\Martin Prikryl\WinSCP 2\Sessions]
- %LOCALAPPDATA%\microsoft\edge\user data\default\web data
- %LOCALAPPDATA%\microsoft\edge\user data\default\login data
- %TEMP%\stealer_data_1773364447_4284\screenshot.jpg
- %TEMP%\temp_login_1773364493.db
- %TEMP%\temp_cards_1773364493.db
- %TEMP%\temp_webdata_1773364493.db
- %TEMP%\stealer_data_1773364447_4284\system_info.txt
- %TEMP%\temp_webdata_1773364493_4284.db
- %TEMP%\ru_185_93_40_66.zip
- %TEMP%\temp_webdata_1773364493_4284.db
- %TEMP%\ru_185_93_40_66.zip
- %TEMP%\stealer_data_1773364447_4284\screenshot.jpg
- %TEMP%\stealer_data_1773364447_4284\system_info.txt
- %TEMP%\temp_login_1773364493.db
- %TEMP%\temp_cards_1773364493.db
- %TEMP%\temp_webdata_1773364493.db
- 'ip##pi.com':80
- '15#.#40.151.134':80
- /json/?fi############################# via ip##pi.com
- /upload via 15#.#40.151.134
- '15#.#40.151.134':80
- DNS ASK ip##pi.com