Техническая информация
- %TEMP%\hibc8ba.exe
- 'd3#######4m94x.cloudfront.net':80
- '52.#.45.42':80
- http://d3#######4m94x.cloudfront.net/SilentInstaller_dotnet4.exe
- DNS ASK d3#######4m94x.cloudfront.net
- DNS ASK ev####.#astmediaplayer.net
- '%TEMP%\hibc8ba.exe' -domain=RsmGwDse.com -dotnet=4 -event=2 -file=moshe -ip=52.1.45.42:80 -s=1