Техническая информация
- %TEMP%\xaaz0pksws8hah
- %TEMP%\xaaz0pksws8hah.dll
- '18#.#27.249.203':80
- '51.##4.55.171':80
- '13#.#01.191.196':80
- http://www.or#d.it/xollrnal
- http://im##.3x.ro/oirjm2
- http://18#.#27.249.203/data/info.php
- DNS ASK tr###xsb.com
- DNS ASK or#d.it
- DNS ASK im##.3x.ro
- '%WINDIR%\syswow64\rundll32.exe' %TEMP%\XAAZ0P~1.DLL,qwerty 323