Техническая информация
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\509858.bat" "<Полный путь к вирусу>" "
- '<SYSTEM32>\rundll32.exe' dfdts.dll,DfdGetDefaultPolicyAndSMART
- %TEMP%\509858.bat
- 'ch###.##ysteviecantdate.com':80
- 'ch#####.#hysteviecantdate.com':80
- 'ch#######.whysteviecantdate.com':80
- DNS ASK ch###.##YSTEVIECANTDATE.COM
- DNS ASK ch#####.#HYSTEVIECANTDATE.COM
- DNS ASK ch#######.WHYSTEVIECANTDATE.COM