Техническая информация
- '%APPDATA%\lsass.exe' <Полный путь к вирусу>
- '<SYSTEM32>\arp.exe' -a
- %APPDATA%\lsass.exe
- 'lo#####o.servegame.com':12001
- 'fo###.##th.garenanow.com':18000
- 'lo#####o.servebeer.com':12001
- 'localhost':12000
- '12#.#53.117.45':18000
- 'lo#####o.servegame.com':18000
- 'lo#####o.servebeer.com':18000
- DNS ASK www.dr##box.com
- DNS ASK wp#d
- DNS ASK dl.#####oxusercontent.com
- DNS ASK www.co##.com
- DNS ASK lo#####o.servegame.com
- DNS ASK lo#####o.servebeer.com
- DNS ASK fo###.##th.garenanow.com
- ClassName: 'Shell_TrayWnd' WindowName: ''