Техническая информация
- '<SYSTEM32>\regsvr32.exe' ..\hvxda.ocx
- %HOMEPATH%\hvxda.ocx
- %HOMEPATH%\hvxda.ocx в <SYSTEM32>\tybgd\yytkfzzcfeyucbq.dll
- 'ai###ftlimo.com':443
- 'ro####xpenedes.com':80
- 'me####cursos.com.br':443
- 'li####ape.com.my':443
- 'x1.#.lencr.org':80
- 'r3.#.lencr.org':80
- 'ol#.#iceum9.ru':80
- 'oc##.thawte.com':80
- http://ro####xpenedes.com/wp-admin/2TH6NO3/
- http://x1.#.lencr.org/
- http://r3.#.lencr.org/MFMwUTBPME0wSzAJBgUrDgMCGgUABBRI2smg%2ByvTLU%2Fw3mjS9We3NfmzxAQUFC6zF7dYVsuuUAlA5h%2BvnYsUwsYCEgP8F3hjJ7uqNfwy1Dk8P7jXPw%3D%3D
- http://ol#.#iceum9.ru/images/R/
- http://oc##.thawte.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQwF4prw9S7mCbCEHD%2Fyl6nWPkczAQUe1tFz6%2FOy3r9MZIaarbzRutXSFACEEeXTXhzpbyrDS%2BzcBkvzl4%3D
- 'ai###ftlimo.com':443
- 'me####cursos.com.br':443
- 'li####ape.com.my':443
- DNS ASK ai###ftlimo.com
- DNS ASK ro####xpenedes.com
- DNS ASK me####cursos.com.br
- DNS ASK li####ape.com.my
- DNS ASK x1.#.lencr.org
- DNS ASK r3.#.lencr.org
- DNS ASK ol#.#iceum9.ru
- DNS ASK oc##.thawte.com
- '<SYSTEM32>\regsvr32.exe' ..\hvxda.ocx' (со скрытым окном)
- '<SYSTEM32>\regsvr32.exe' "<SYSTEM32>\TYbgd\YytKfzzcFeyucbq.dll"