Техническая информация
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe'
- eqnedt32.exe
- %TEMP%\dcnx18pwh.wmf
- %TEMP%\dcnx18pwh.wmf
- '13#.#20.176.165':443
- 'r3.#.lencr.org':80
- 'x1.#.lencr.org':80
- 'oc##.thawte.com':80
- 'oc##.#tartssl.com':80
- http://r3.#.lencr.org/
- http://x1.#.lencr.org/
- http://oc##.thawte.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQwF4prw9S7mCbCEHD%2Fyl6nWPkczAQUe1tFz6%2FOy3r9MZIaarbzRutXSFACEEeXTXhzpbyrDS%2BzcBkvzl4%3D
- http://oc##.#tartssl.com/sub/class2/code/ca/MEMwQTA%2FMD0wOzAJBgUrDgMCGgUABBQSOgrhRCSnWfKxoWTjWxhk8hga9AQU0E4PQJlsuEsZbzsouODjiAc0qrcCAhAV
- '13#.#20.176.165':443
- DNS ASK r3.#.lencr.org
- DNS ASK x1.#.lencr.org
- DNS ASK oc##.thawte.com
- DNS ASK oc##.#tartssl.com
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding