Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'kmyckuum.exe' = '"%APPDATA%\Identities\kmyckuum.exe"'
- <SYSTEM32>\cmd.exe
- %APPDATA%\ms2526488.bat
- %APPDATA%\Identities\kmyckuum.exe
- %APPDATA%\ms2526488.bat
- '20#.#6.232.182':80
- 20#.#6.232.182/
- DNS ASK www.microsoft.com
- ClassName: '' WindowName: 'ig t'
- ClassName: '' WindowName: 'miOD'
- ClassName: 'Indicator' WindowName: ''
- ClassName: '' WindowName: 'gdMfh'
- ClassName: '' WindowName: 'LeKCBTje tiGw'
- ClassName: '' WindowName: 'Cy Ydjzxb'
- ClassName: '' WindowName: 'aN'