Техническая информация
- %TEMP%\edge.dll
- '<SYSTEM32>\cmd.exe'
- <SYSTEM32>\cmd.exe
- %HOMEPATH%\application data\microsoft\forms\winword.box
- %TEMP%\edge.dll
- %TEMP%\1055408.dat
- %TEMP%\1055409.dat
- http://oc##.#tartssl.com/sub/class2/code/ca/MEMwQTA%2FMD0wOzAJBgUrDgMCGgUABBQSOgrhRCSnWfKxoWTjWxhk8hga9AQU0E4PQJlsuEsZbzsouODjiAc0qrcCAhAV
- DNS ASK pa###bin.com
- DNS ASK oc##.#tartssl.com