Техническая информация
- [<HKLM>\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000003] 'LibraryPath' = 'mswsock.dll'
- <SYSTEM32>\services.exe
- %WINDIR%\Explorer.EXE
- C:\RECYCLER\S-1-5-18\$2ebe1c2e2a38cb36436c4d1cb8c2630c\n
- C:\RECYCLER\S-1-5-21-2052111302-484763869-725345543-1003\$I58AFF310
- %WINDIR%\assembly\GAC\Desktop.ini
- C:\RECYCLER\S-1-5-21-2052111302-484763869-725345543-1003\$2ebe1c2e2a38cb36436c4d1cb8c2630c\@
- C:\RECYCLER\S-1-5-21-2052111302-484763869-725345543-1003\$2ebe1c2e2a38cb36436c4d1cb8c2630c\n
- C:\RECYCLER\S-1-5-18\$2ebe1c2e2a38cb36436c4d1cb8c2630c\@
- из <Полный путь к вирусу> в C:\RECYCLER\S-1-5-21-2052111302-484763869-725345543-1003\$R58AFF310
- 'j.###mind.com':80
- j.###mind.com/app/geoip.js
- DNS ASK �# u�
- DNS ASK �#���A
- DNS ASK �#��s
- DNS ASK �#�^:�
- DNS ASK �#&�R)
- DNS ASK �#�
- DNS ASK j.###mind.com
- DNS ASK �#Ժ�
- DNS ASK �#^
- DNS ASK �#�Ϫ4
- '17#.#02.221.52':16471
- '72.##9.220.50':16471
- '71.##2.138.54':16471
- '24.##2.243.95':16471
- '21#.#03.201.100':16471
- '84.##.240.43':16471
- '88.##0.144.103':16471
- '92.##1.151.101':16471
- '66.#1.8.102':16471
- '71.##.153.79':16471
- '17#.#42.148.83':16471
- '66.##8.151.71':16471
- '18#.#73.11.78':16471
- '24.##5.32.85':16471
- '24.#.0.92':16471
- '71.#1.9.94':16471
- '18#.#0.89.87':16471
- '17#.#25.45.91':16471