Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'kmyckuum.exe' = '"%APPDATA%\Identities\kmyckuum.exe"'
- <SYSTEM32>\cmd.exe
- %APPDATA%\ms6747145.bat
- %APPDATA%\Identities\kmyckuum.exe
- %APPDATA%\ms6747145.bat
- '20#.#6.232.182':80
- 20#.#6.232.182/
- DNS ASK www.microsoft.com
- ClassName: '' WindowName: 'EaXF m'
- ClassName: '' WindowName: 'golQnxk TrCguSu'
- ClassName: 'Indicator' WindowName: ''
- ClassName: '' WindowName: 'DavyLAsCAmrf'
- ClassName: '' WindowName: 'uoxHdf'
- ClassName: '' WindowName: 'yl awep e'