Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'imapi.exe' = '%APPDATA%\Mozilla\Extensions\extrac32.exe'
- %WINDIR%\Explorer.EXE
- %APPDATA%\Mozilla\Extensions\extrac32.exe
- 'fd######joh38w3m.oogagh.su':443
- 'h1#####nqmm.tohk5ja.cc':443
- 'b4####i.thepohzi.su':443
- DNS ASK fd######joh38w3m.oogagh.su
- DNS ASK h1#####nqmm.tohk5ja.cc
- DNS ASK b4####i.thepohzi.su
- ClassName: 'Indicator' WindowName: ''