Техническая информация
- <SYSTEM32>\rundll32.exe "%TEMP%\ins1.tmp",wvpfmzkdjzwvdp install
- %TEMP%\ins1.tmp
- 'wo###nen.co.be':80
- wo###nen.co.be/mrroZZEKXuQd/UnIkjgQT4gcefxqMlGN2MMPHHWKivkFuggX9tS4JAim3Dl8jr6/2aWhNxOPuayi7KVqgbdQDmkenn9sM9xh/DJEFOMYPL4Qqg==
- wo###nen.co.be/wDgVEZyQdPHwIsCobmqBvE7n9J/obfaKZy3CJBYeeCulcGSaiN9AM8vMDpOxhq/MDRJiDSIKk+i/y/eOohwD4hlXsnas00kkCQWBOXjUPQMjFByhMt74tXiKJv/q8Mj8HTvOaQKxMpRFFU1TyV/BSQc0iYKGh/H7vk+jW4kkAhk7hchddYztUqec1NdKm9tlD+MwBCUxfXk=
- DNS ASK wo###nen.co.be
- '<IP-адрес в локальной сети>':1035
- ClassName: 'Shell_TrayWnd' WindowName: ''