Техническая информация
- <SYSTEM32>\dllhost.exe
- Процесс qelwsop.exe, модуль Amsi.dll
- %LOCALAPPDATA%\microsoft\edge\user data\default\login data
- %LOCALAPPDATA%\google\chrome\user data\default\login data
- %LOCALAPPDATA%\microsoft\edge\user data\default\web data
- %LOCALAPPDATA%\google\chrome\user data\default\cookies
- %LOCALAPPDATA%\google\chrome\user data\default\web data
- %TEMP%\msdia_0000041c\000e3525.tmp
- %TEMP%\msdia_0000041c\000ee962.tmp
- %TEMP%\msdia_0000041c\000f2ce3.tmp
- %TEMP%\msdia_0000041c\000fb3d6.tmp
- %TEMP%\msdia_0000041c\000e3525.tmp
- %TEMP%\msdia_0000041c\000ee962.tmp
- %TEMP%\msdia_0000041c\000f2ce3.tmp
- %TEMP%\msdia_0000041c\000fb3d6.tmp
- 'ca####gshops.info':443
- 'x1.#.lencr.org':80
- 'ca####gshops.info':443
- DNS ASK ca####gshops.info
- DNS ASK x1.#.lencr.org
- DNS ASK time.google.com
- 'time.google.com':123
- '<SYSTEM32>\dllhost.exe' (со скрытым окном)