Техническая информация
- '%TEMP%\vicsapis.exe'
- '<SYSTEM32>\conhost.exe' /Processid:{F9717507-6651-4EDB-BFF7-AE615179BCCF}
- %TEMP%\vicsapis.exe
- %TEMP%\Tmp5233.txt
- '17#.#48.27.163':443
- '17#.#43.255.79':443
- '17#.#48.31.6':443
- '17#.#48.22.227':443
- '17#.#48.31.1':443
- '69.#.204.114':443
- '71.##4.36.73':443
- '98.##2.64.184':443
- '76.#8.92.4':443
- '73.##5.203.173':443
- '18#.#55.239.34':443
- '18#.#55.165.154':443
- '17#.#16.240.56':443
- '17#.#6.251.208':443
- '10#.#6.226.85':443
- '24.##0.92.193':443
- '69.##3.81.211':443
- '72.##0.82.80':443
- '64.##3.121.6':443
- '10#.#74.123.66':443
- '21#.#54.231.11':443
- '24.##.131.116':443
- DNS ASK dn#.##ftncsi.com
- DNS ASK ic###azip.com
- ClassName: 'Shell_TrayWnd' WindowName: ''