Техническая информация
- <SYSTEM32>\rundll32.exe "%TEMP%\ins1.tmp",tbjcuymnbt install
- %TEMP%\ins1.tmp
- 'ho##y.cz.cc':80
- ho##y.cz.cc/SzQTxgrjtEYcMtz93z+OHEPYEMc8S7VxNSK8gG5C00lhFgMpPDBKrM4H3xLJc9TV0qyNGSilXlnnTXGJEvo28XCHWLHtsFUs+WepZBbS2Qs/Ng==
- ho##y.cz.cc/tACOyvsaXbSmMV3S0TK0fCYSI4WuTTIoG1ye1/cng+pyPhUH7+dM+MSkbSeZ2EW/dDWcJ8SUp17zmUjs4n3LezcapZl/ZO4pi7PJOeITc9dPqj3HxpNyvom6LaXwUMiU0y/3PnZjVQzUpS2HBmJ6k4hbUmbOTc6gLo9Sb2IgdAeFoM0VKnjUQCm2evdrvELFVGcxk4S0iVo=
- DNS ASK ho##y.cz.cc
- '<IP-адрес в локальной сети>':1035
- ClassName: 'Shell_TrayWnd' WindowName: ''