Техническая информация
- '<SYSTEM32>\rundll32.exe' %PROGRAMDATA%\goBdwcB.dll,f1
- http://oc##.#tartssl.com/sub/class2/code/ca/MEMwQTA%2FMD0wOzAJBgUrDgMCGgUABBQSOgrhRCSnWfKxoWTjWxhk8hga9AQU0E4PQJlsuEsZbzsouODjiAc0qrcCAhAV
- DNS ASK st###diato.at
- DNS ASK oc##.#tartssl.com
- '<SYSTEM32>\rundll32.exe' %PROGRAMDATA%\goBdwcB.dll,f1' (со скрытым окном)