Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] '{1D476073-5E7F-AD41-B897-60D4A63F43C6}' = '"%APPDATA%\Ekhyq\axdyu.exe"'
- [<HKLM>\SYSTEM\ControlSet001\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] 'DisableNotifications' = '00000001'
- '%APPDATA%\Ekhyq\axdyu.exe'
- <SYSTEM32>\cmd.exe
- <SYSTEM32>\cscript.exe
- %WINDIR%\Explorer.EXE
- <SYSTEM32>\ctfmon.exe
- %TEMP%\tmpb2a9cc30.bat
- <LS_APPDATA>\urdis.omj
- %APPDATA%\Ekhyq\axdyu.exe
- '74.##5.232.51':80
- 74.##5.232.51/
- DNS ASK www.bing.com
- DNS ASK www.google.com
- DNS ASK to#######inbmpjvctvspkqwqk.net
- DNS ASK oz#######xhtkljmjyphztkzkv.org
- '76.##8.85.42':29536
- '76.##6.141.113':22769
- '20#.#3.157.51':11413
- '80.##2.59.142':18633
- '18#.#95.172.56':18503
- '87.#.135.46':10028
- '19#.#4.127.98':25549
- '81.##6.230.235':29447
- '50.##7.96.104':27460
- '19#.#9.195.12':15420
- '76.##.128.171':24685
- '99.##6.113.129':29551
- '99.##3.42.49':26480
- '10#.#3.233.190':15683
- '65.##.235.106':14306
- '64.##9.114.114':13503
- '72.##2.76.111':17515
- '20#.#0.43.247':10151
- ClassName: 'Indicator' WindowName: '(null)'