Техническая информация
- '%TEMP%\holla'
- %WINDIR%\explorer.exe
- holla
- %TEMP%\holla
- %TEMP%\holla
- '19#.#36.147.189':80
- 'pl####umcsltd.com':80
- 'bi###efi.com':80
- 'as######onenterprises.com':80
- 'ms##ax.com':80
- 'po###est.com':80
- 'cc##yyl.com':80
- 'ww##y.com':80
- 'qu###side.net':80
- http://19#.#36.147.189/jefe/holla.exe
- DNS ASK ic##a.com
- DNS ASK pl####umcsltd.com
- DNS ASK bi###efi.com
- DNS ASK as######onenterprises.com
- DNS ASK ms##ax.com
- DNS ASK po###est.com
- DNS ASK cc##yyl.com
- DNS ASK nu######gencysuccess.com
- DNS ASK ww##y.com
- DNS ASK qu###side.net
- '%WINDIR%\syswow64\cmmon32.exe'
- '%WINDIR%\syswow64\cmd.exe' del "%TEMP%\holla"