Техническая информация
- '%APPDATA%\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\lsass.exe'
- <SYSTEM32>\taskhost.exe
- <SYSTEM32>\Dwm.exe
- %WINDIR%\Explorer.EXE
- %APPDATA%\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\lsass.exe
- 'www.ou####ysfamily.com':80
- www.ou####ysfamily.com/create/a1/index.php
- DNS ASK www.ou####ysfamily.com