Техническая информация
- %HOMEPATH%\Start Menu\Programs\Startup\lsass.exe
- '%HOMEPATH%\Start Menu\Programs\Startup\lsass.exe'
- '<SYSTEM32>\notepad.exe' -f ".\torrc"
- <SYSTEM32>\cscript.exe
- %APPDATA%\tor\state.tmp
- %APPDATA%\tor.bin
- %APPDATA%\torrc
- %APPDATA%\tor\state.tmp в %APPDATA%\tor\state
- '21#.#12.245.170':443
- '15#.35.32.5':443
- 'localhost':1035
- DNS ASK ip.#omax.fr
- DNS ASK ip#.###update.no-ip.com
- DNS ASK ap#.###p.org?call=ip
- DNS ASK ip##.#canhazip.com
- DNS ASK my##.#nsomatic.com