Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'zXTSIhsvhvIuLwDeLpEuVPjFFcRMdmLXjRqlr' = '%APPDATA%\zXTSIhsvhvIuLwDeLpEuVPjFFcRMdmLXjRqlr.exe'
- '%APPDATA%\zXTSIhsvhvIuLwDeLpEuVPjFFcRMdmLXjRqlr.exe'
- '<SYSTEM32>\ping.exe' 1.1.1.1 -n 1 -w 1
- %APPDATA%\zXTSIhsvhvIuLwDeLpEuVPjFFcRMdmLXjRqlr.exe
- 'su######thers.serveftp.com':80
- su######thers.serveftp.com/venny/gate.php
- DNS ASK su######thers.serveftp.com