Техническая информация
- '%CommonProgramFiles%\%SESSIONNAME%\cfmon.exe'
- '<SYSTEM32>\wscript.exe' "%PROGRAM_FILES%\MJO.VBE"
- '<SYSTEM32>\taskkill.exe' /im cfmon.exe /f
- %PROGRAM_FILES%\MJO.VBE
- %CommonProgramFiles%\%SESSIONNAME%\cfmon.exe
- 'd.###6800.com':80
- 'localhost':1036
- d.###6800.com/b.jpg
- DNS ASK d.###6800.com
- ClassName: '(null)' WindowName: '(null)'