Техническая информация
- http://18#.#12.249.122/warjack_ae8d.exe как %appdata%\warjack_ae8d.exe
- %WINDIR%\syswow64\cmd.exe
- warjack_ae8d.exe
- %TEMP%\abctfhghghghghВЈ.sct
- %PROGRAMDATA%\hrjytrj.cmd
- %APPDATA%\warjack_ae8d.exe
- 'sr#####jf.rapiddns.ru':6703
- http://18#.#12.249.122/warjack_AE8D.exe
- http://18#.#12.249.122/warjack_encrypted_B2183EF.bin
- DNS ASK sr#####jf.rapiddns.ru
- '%APPDATA%\warjack_ae8d.exe'
- '%WINDIR%\syswow64\cmd.exe'