Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\Chanternt] 'Start' = '00000002'
- '%WINDIR%\Web\iuwfirwf.exe'
- 'C:\programdata\reasce.exe'
- '%WINDIR%\Web\iuwfirwf.exe' (загружен из сети Интернет)
- '<SYSTEM32>\wbem\wmiadap.exe' /R /T
- '<SYSTEM32>\sc.exe' Create Chanternt binPath= "cmd /c start c:\programdata\reasce.vbs" type= own type= interact start= auto
- %WINDIR%\Web\iuwfirwf.exe
- C:\programdata\reasce.vbs
- C:\programdata\reasce.exe
- 'www.om##8.com':80
- 'www.sh###ail.com':80
- 'ru#####on.firstmall.kr':80
- www.om##8.com/seo/xxx2.jpg
- www.sh###ail.com/data/page/pa02/b.txt
- ru#####on.firstmall.kr/data/board/qna/f653c141720945455
- DNS ASK www.om##8.com
- DNS ASK www.sh###ail.com
- DNS ASK ru#####on.firstmall.kr