Техническая информация
- %TEMP%\cyt6rhjoxa5g
- %TEMP%\cyt6rhjoxa5g.dll
- http://an######nelli.interfree.it/rfer0z1
- DNS ASK wa###ewang.name
- DNS ASK an######nelli.interfree.it
- DNS ASK pe#####ebsite.dommel.be
- '%WINDIR%\syswow64\rundll32.exe' %TEMP%\CYT6RH~1.DLL,qwerty 323