Техническая информация
- %APPDATA%\binwealther46573.exe
- http://ad####epartment.ir/wealthx/binwealth.exe
- http://ad####epartment.ir/cgi-sys/suspendedpage.cgi
- DNS ASK ad####epartment.ir
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding