Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '{7B75138C-E213-D060-4943-4BCABEE165F7}' = '%APPDATA%\zBEGKSPu\HILbWymN\ThllEmqx\tlablYjIm.exe'
- %WINDIR%\Tasks\{7B75138C-E213-D060-4943-4BCABEE165F7}.job
- '%APPDATA%\zBEGKSPu\HILbWymN\ThllEmqx\tlablYjIm.exe'
- %APPDATA%\zBEGKSPu\HILbWymN\ThllEmqx\tlablYjIm.exe
- 'ta###peri.party':80
- 'tu####usim.party':80
- 'pr#.###friendlythai.com':80
- 'lo###onenet.com':80
- http://ta###peri.party/netreport.php
- http://tu####usim.party/netreport.php
- http://pr#.###friendlythai.com/netreport.php
- http://lo###onenet.com/netreport.php
- DNS ASK ta###peri.party
- DNS ASK tu####usim.party
- DNS ASK pr#.###friendlythai.com
- DNS ASK lo###onenet.com