Техническая информация
- [HKLM\SYSTEM\CurrentControlSet\Services\Transaction Acquisition WinHTTP Secondary] 'Start' = '00000002'
- [HKLM\SYSTEM\CurrentControlSet\Services\Transaction Acquisition WinHTTP Secondary] 'ImagePath' = 'C:\cygmdigo\hgdsfqaof.exe'
- 'Transaction Acquisition WinHTTP Secondary' C:\cygmdigo\hgdsfqaof.exe
- %WINDIR%\cygmdigo\xuccly
- C:\cygmdigo\xuccly
- C:\cygmdigo\qy8iq2hjhmjz6aeo5f.exe
- C:\cygmdigo\hgdsfqaof.exe
- C:\cygmdigo\nejwdngdgoh.exe
- C:\cygmdigo\hgdsfqaof.exe
- C:\cygmdigo\nejwdngdgoh.exe
- %WINDIR%\cygmdigo\xuccly
- C:\cygmdigo\qy8iq2hjhmjz6aeo5f.exe
- %WINDIR%\cygmdigo\xuccly
- DNS ASK co####ecentury.net
- DNS ASK ch###famous.net
- DNS ASK co####efamous.net
- 'C:\cygmdigo\qy8iq2hjhmjz6aeo5f.exe'
- 'C:\cygmdigo\hgdsfqaof.exe'
- 'C:\cygmdigo\nejwdngdgoh.exe' "c:\cygmdigo\hgdsfqaof.exe"