Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\RpcSRPG] 'Start' = '00000002'
- '%PROGRAM_FILES%\Windows NT\inetnfo.exe' -k
- '<SYSTEM32>\wscript.exe' "<Текущая директория>\tem.vbs"
- C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\CJCTQ25G\injection[1].dll
- <SYSTEM32>\injection.dll
- %PROGRAM_FILES%\Windows NT\inetnfo.exe
- <Текущая директория>\tem.vbs
- <Текущая директория>\tem.vbs
- 'be#####.##s-cn-qingdao.aliyuncs.com':80
- 'localhost':1040
- be#####.##s-cn-qingdao.aliyuncs.com/injection.dll
- DNS ASK be#####.##s-cn-qingdao.aliyuncs.com