Техническая информация
- '<SYSTEM32>\rundll32.exe' %PROGRAMDATA%\zGCORgC.dll,DllRegisterServer
- %WINDIR%\syswow64\msiexec.exe
- %PROGRAMDATA%\zgcorgc.dll
- %APPDATA%\ufip\ripayho.dll
- http://wm######xxbcxmucxmlc.com/files/april17.dll
- http://www.sn######hflwgthqismb.com/post.php
- http://wm######xxbcxmucxmlc.com/post.php
- http://oj######lftfkkuxxiqd.com/post.php
- http://pw######tsshkoibaake.com/post.php
- http://sn######hflwgthqismb.com/post.php
- DNS ASK wm######xxbcxmucxmlc.com
- DNS ASK oj######lftfkkuxxiqd.com
- DNS ASK pw######tsshkoibaake.com
- DNS ASK sn######hflwgthqismb.com
- '<SYSTEM32>\rundll32.exe' %PROGRAMDATA%\zGCORgC.dll,DllRegisterServer' (со скрытым окном)
- '%WINDIR%\syswow64\msiexec.exe'