Техническая информация
- '<SYSTEM32>\wscript.exe' "%WINDIR%\Temp\hjdmpwjbbs.js"
- %WINDIR%\temp\hjdmpwjbbs.js
- http://ze###opats.com/angosz/cecolf.php?l=##########
- http://se###lcury.com/Toqis.php
- DNS ASK tr###micro.com
- DNS ASK ze###opats.com
- DNS ASK se###lcury.com
- ClassName: 'Ghost' WindowName: ''