Техническая информация
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1528
- %TEMP%\1120617.cvr
- 'vi####can.jotti.org':443
- 'x1.#.lencr.org':80
- 'r3.#.lencr.org':80
- http://x1.#.lencr.org/
- http://r3.#.lencr.org/MFMwUTBPME0wSzAJBgUrDgMCGgUABBRI2smg%2ByvTLU%2Fw3mjS9We3NfmzxAQUFC6zF7dYVsuuUAlA5h%2BvnYsUwsYCEgPxfXHJssAVHkJey84ieEo58w%3D%3D
- 'vi####can.jotti.org':443
- DNS ASK vi####can.jotti.org
- DNS ASK x1.#.lencr.org
- DNS ASK r3.#.lencr.org
- DNS ASK st####.rapidssl.com
- '<SYSTEM32>\mshta.exe' hTTps://virusscan.joTTi.org/en-US/filescanjob/33simievaf