Техническая информация
- <SYSTEM32>\rundll32.exe "%TEMP%\ins1.tmp",xncujvchq install
- %TEMP%\ins1.tmp
- 'kc###wsko.ce.ms':80
- kc###wsko.ce.ms/mDoNfsGVfTQy27NRMxwdQLt516L7AEBU62D51AUUhP9rlZ15xpTMz8DSfWIpMrNjYut3BdsP8tJ8tUgUjYwBbCmRS55env7uGS1Tz4tlvv8=
- kc###wsko.ce.ms/NCKKcWmuo9QnL9GCodOq4QeDcVvB98thKkO3KLBOQz7BvS92looUbHko/UyoWxDZbIPnAbs/85loEZjzgNw3Ku5Lcj298vSVu8zu76xkcWzWGjWoC9CLC8BaolmGfi6HErrnL7Vlz1Gf5n3tbqTYiIrKPSID7euOxRHh23bkVK/80xh8GtGMCMqlomil1hWgDSD8QQDS
- DNS ASK kc###wsko.ce.ms
- '<IP-адрес в локальной сети>':1035
- ClassName: 'Shell_TrayWnd' WindowName: ''