Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'REGISTRY' = '<LS_APPDATA>\pulaosugiingat.exe'
- <LS_APPDATA>\chynbfhtvvatng.exe "<LS_APPDATA>\pulaosugiingat.exe"
- <LS_APPDATA>\pulaosugiingat.exe
- <LS_APPDATA>\pulaosugiingat.rng
- <LS_APPDATA>\chynbfhtvvatng.exe
- <LS_APPDATA>\pulaosugiingat.exe
- <LS_APPDATA>\chynbfhtvvatng.exe
- <LS_APPDATA>\pulaosugiingat.exe
- 'su###ulos.com':80
- 'sl###zincur.com':80
- 'pu###edos.com':80
- su###ulos.com/forum/search.php
- sl###zincur.com/forum/search.php
- pu###edos.com/forum/search.php
- DNS ASK su###ulos.com
- DNS ASK sl###zincur.com
- DNS ASK pu###edos.com
- ClassName: 'Indicator' WindowName: ''