Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'kmyckuum.exe' = '"%APPDATA%\Identities\kmyckuum.exe"'
- <SYSTEM32>\cmd.exe
- %APPDATA%\ms2531612.bat
- %APPDATA%\Identities\kmyckuum.exe
- %APPDATA%\ms2531612.bat
- '20#.#6.232.182':80
- 20#.#6.232.182/
- DNS ASK www.microsoft.com
- ClassName: '' WindowName: 'ftcl qlyjVChi'
- ClassName: '' WindowName: 'mflhcps E Xk'
- ClassName: 'Indicator' WindowName: ''
- ClassName: '' WindowName: 'JU ss'
- ClassName: '' WindowName: 'zcd dijzpx'
- ClassName: '' WindowName: 'oKW'
- ClassName: '' WindowName: ' isZ'