Техническая информация
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1452
- %APPDATA%\11560.xsl
- %TEMP%\1190381.cvr
- %WINDIR%\temp\5j3h9.dll
- 'cu#####istributions.com':443
- 'el#####cardsystems.com':80
- http://el#####cardsystems.com/plugins/vmcustom/specification/specification/tmpl/R674L7LjbwF.php
- 'cu#####istributions.com':443
- DNS ASK si###.####apropertylistingsea.com
- DNS ASK cu#####istributions.com
- DNS ASK ka######ashramlimbdi.com
- DNS ASK el#####cardsystems.com
- ClassName: 'coNSOLEWInDOWCLASs' WindowName: ''
- '<SYSTEM32>\wbem\wmic.exe' ' (со скрытым окном)
- '<SYSTEM32>\wbem\wmic.exe'
- '<SYSTEM32>\rundll32.exe' C:/Windows/Temp//5j3h9.dll DllRegisterServer