Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'BlackHole Remote Control Services' = 'rundll32.exe brc_Server.dll,ServiceMainManual'
- '<SYSTEM32>\rundll32.exe' brc_Server.dll,ServiceMainManual
- <SYSTEM32>\brc_Server.dat
- <SYSTEM32>\brc_Server.dll
- <SYSTEM32>\brc_Server.exe
- 'we#.59cn.cn':80
- we#.59cn.cn/2342349/ip.txt
- DNS ASK we#.59cn.cn
- ClassName: 'Indicator' WindowName: '(null)'