Техническая информация
- <SYSTEM32>\rsnotify.exe
- %TEMP%\icon.ico
- <DRIVERS>\etc\hosts
- DNS ASK pi##iuwu.cn
- DNS ASK b.###bkj.com
- DNS ASK to###.#e.cdn.dnsv1.com
- DNS ASK to##u.me
- '<SYSTEM32>\cmd.exe' /c cacls.exe <DRIVERS>\etc\hosts /e /t /p everyone:F' (со скрытым окном)
- '<SYSTEM32>\rsnotify.exe' 100861008671
- '<SYSTEM32>\cmd.exe' /c cacls.exe <DRIVERS>\etc\hosts /e /t /p everyone:F
- '<SYSTEM32>\cacls.exe' <DRIVERS>\etc\hosts /e /t /p everyone:F