Техническая информация
- '<SYSTEM32>\cscript.exe' /NoLogo C:\Users\Public\l9pnyFSEmjNr\dixFfyiM9aHoy.vbs
- '<SYSTEM32>\regsvr32.exe' /si C:\Users\Public\l9pnyFSEmjNr\ubpVd14QPwgFw1.dll
- <SYSTEM32>\wermgr.exe
- C:\users\public\l9pnyfsemjnr\dixffyim9ahoy.vbs
- C:\users\public\l9pnyfsemjnr\ubpvd14qpwgfw1.dll
- C:\users\public\l9pnyfsemjnr\dixffyim9ahoy.vbs
- http://lo####ielajsd.xyz/campo/123
- http://lu###tekkie.ca/t470.dll
- DNS ASK lo####ielajsd.xyz
- DNS ASK lu###tekkie.ca
- '<SYSTEM32>\wermgr.exe'