Техническая информация
- '<SYSTEM32>\rundll32.exe' %PROGRAMDATA%\ieTneVi.dll,DllRegisterServer
- %WINDIR%\syswow64\msiexec.exe
- %PROGRAMDATA%\ietnevi.dll
- %APPDATA%\hium\erek.dll
- http://ma###262020.com/files/april8.dll
- http://ma####62020.best/post.php
- http://ma###262020.com/post.php
- http://ma####62020.live/post.php
- http://ma####62020.network/post.php
- DNS ASK ma###262020.com
- DNS ASK ma####62020.best
- DNS ASK ma####62020.club
- DNS ASK ma####62020.live
- DNS ASK ma####62020.network
- DNS ASK ma####62020.online
- '<SYSTEM32>\rundll32.exe' %PROGRAMDATA%\ieTneVi.dll,DllRegisterServer' (со скрытым окном)
- '%WINDIR%\syswow64\msiexec.exe'