Техническая информация
- http://10#.#01.143.181/word/binn_2806.exe как %appdata%\binn_2806.exe
- binn_2806.exe
- %TEMP%\abctfhghghghghВЈ.sct
- %PROGRAMDATA%\hrjytrj.cmd
- %APPDATA%\binn_2806.exe
- '35.##8.134.218':80
- http://10#.#01.143.181/word/binn_2806.exe
- http://10#.#01.143.181/binn/binn_encrypted_ACA9B0.bin
- http://35.##8.134.218/gate/log.php
- DNS ASK do#########ocs.googleusercontent.com
- '%APPDATA%\binn_2806.exe'