Техническая информация
- [<HKCU>\Software\Microsoft\Windows\CurrentVersion\Run] 'C0FD6811' = '%APPDATA%\C0FD6811\bin.exe'
- '%WINDIR%\explorer.exe'
- <SYSTEM32>\cscript.exe
- %APPDATA%\C0FD6811\bin.exe
- %APPDATA%\C0FD6811\log.dat
- 'jw#####328hdy3tep.cc':80
- http://jw#####328hdy3tep.cc/n0tru2t76hw2edqj/
- DNS ASK jw#####328hdy3tep.cc
- ClassName: 'Indicator' WindowName: ''