Техническая информация
- %WINDIR%\explorer.exe
- %TEMP%\nsh2646.tmp
- %TEMP%\ad4t6uyj2xx
- %TEMP%\1d0b7tsxg71wo
- %TEMP%\nsc2676.tmp\4t8tohsqhlstl.dll
- 'em##ist.com':80
- 'vi##ito.com':80
- 'ea#######anddowntrucking.com':80
- 'do##z.com':80
- 'xn#####irelik-u3a.com':80
- DNS ASK em##ist.com
- DNS ASK vi##ito.com
- DNS ASK ea#######anddowntrucking.com
- DNS ASK do##z.com
- DNS ASK xn#####irelik-u3a.com
- '%WINDIR%\syswow64\wuapp.exe'
- '%WINDIR%\syswow64\cmd.exe' del "<Полный путь к файлу>"