Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'BDC91373' = '%APPDATA%\BDC91373\bin.exe'
- '%WINDIR%\explorer.exe'
- <SYSTEM32>\cscript.exe
- %APPDATA%\BDC91373\bin.exe
- 'mg###lmmjiiy.pw':80
- http://mg###lmmjiiy.pw/HUERuV20Bb/
- DNS ASK mg###lmmjiiy.pw
- ClassName: 'Indicator' WindowName: ''