Техническая информация
- %HOMEPATH%\Start Menu\Programs\Startup\lsass.exe
- '%HOMEPATH%\Start Menu\Programs\Startup\lsass.exe'
- '<SYSTEM32>\notepad.exe' -f ".\torrc"
- <SYSTEM32>\notepad.exe
- %APPDATA%\tor\state.tmp
- %APPDATA%\torrc
- %APPDATA%\tor.bin
- %APPDATA%\tor\state.tmp в %APPDATA%\tor\state
- 'ip.#omax.fr':80
- 'ap#.###p.org?call=ip':80
- 'ip#.###update.no-ip.com':80
- 'localhost':9002
- 'if##nfig.me':80
- '86.#9.21.38':443
- 'localhost':1037
- '76.##.17.194':9090
- 'my##.#nsomatic.com':80
- 'ip##.#canhazip.com':80
- ip.#omax.fr/
- ip#.###update.no-ip.com/
- if##nfig.me/ip
- ip##.#canhazip.com/
- my##.#nsomatic.com/
- ap#.###p.org?call=ip/
- DNS ASK ip.#omax.fr
- DNS ASK ip#.###update.no-ip.com
- DNS ASK if##nfig.me
- DNS ASK ip##.#canhazip.com
- DNS ASK my##.#nsomatic.com
- DNS ASK ap#.###p.org?call=ip