Техническая информация
- %WINDIR%\explorer.exe
- %TEMP%\nelesqcpqe.exe
- %TEMP%\nqgkeplnvs.jpg
- %TEMP%\ixp000.tmp\server2.exe
- %TEMP%\dmscpbykdr.exe
- %TEMP%\vrpeigpmyn.exe
- %TEMP%\ixp000.tmp\server2.exe
- http://www.yo###ebsite.com/yourfile.jpg
- DNS ASK yo###ebsite.com
- '%TEMP%\nelesqcpqe.exe'
- '%TEMP%\ixp000.tmp\server2.exe'
- '%TEMP%\dmscpbykdr.exe'
- '%TEMP%\vrpeigpmyn.exe'
- '%TEMP%\ixp000.tmp\server2.exe' ' (со скрытым окном)
- '%WINDIR%\syswow64\rundll32.exe' url.dll,FileProtocolHandler C:\SetUp.exe