Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'wincl' = '%APPDATA%\WinSlm\winslm.exe'
- '%APPDATA%\WinSlm\winslm.exe'
- %APPDATA%\WinSlm\winslm.exe
- %APPDATA%\__check__2364.xyz
- %APPDATA%\__check__2364.xyz
- 'www.wa##r.net':80
- 'me###ldavid.com':80
- 'ru###kutai.com':80
- 'www.an#####fhearts.co.za':80
- 'www.ga#####koochooloo.com':80
- 'www.ma#####zvillarroya.es':80
- http://www.wa##r.net/
- http://me###ldavid.com/
- http://ru###kutai.com/
- http://www.an#####fhearts.co.za/wp-content/plugins/WPCoreLog/log.php?rn#######
- http://www.ga#####koochooloo.com/
- http://www.ma#####zvillarroya.es/
- DNS ASK www.wa##r.net
- DNS ASK me###ldavid.com
- DNS ASK ru###kutai.com
- DNS ASK www.an#####fhearts.co.za
- DNS ASK www.ga#####koochooloo.com
- DNS ASK www.ma#####zvillarroya.es
- ClassName: 'Indicator' WindowName: ''