Техническая информация
- %WINDIR%\syswow64\svchost.exe
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\ie\ukx9oycx\service[1].htm
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\ie\t7jbxaoa\service[1].htm
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\ie\t7jbxaoa\ycl[1].htm
- 'drive.usercontent.google.com':443
- '23.##5.2.149':80
- '15#.#4.209.95':80
- http://15#.#4.209.95/success?su##########################
- 'drive.usercontent.google.com':443
- DNS ASK drive.usercontent.google.com
- '%WINDIR%\syswow64\svchost.exe'