Техническая информация
- http://ha##bu.jp/wp/reservati9.exe как %appdata%\reservati9.exe
- reservati9.exe
- %TEMP%\abctfhghghghghВЈ.sct
- %PROGRAMDATA%\hrjytrj.cmd
- %APPDATA%\reservati9.exe
- %TEMP%\hvuqabnm.exe
- 'do#########ocs.googleusercontent.com':443
- http://ha##bu.jp/wp/Reservati9.exe
- http://ha##bu.jp/wp/hVUqabNM.exe
- DNS ASK ha##bu.jp
- DNS ASK do#########ocs.googleusercontent.com
- '%APPDATA%\reservati9.exe'