Техническая информация
- '%WINDIR%\syswow64\regsvr32.exe' -s ..\xewn.dll
- %TEMP%\error021320_01.xml
- %HOMEPATH%\xewn.dll
- 'go####hhalifax.com':80
- 'go####hhalifax.ca':443
- 'x1.#.lencr.org':80
- 'r3.#.lencr.org':80
- 'tx###escue.com':443
- 'oc##.thawte.com':80
- 'ha###mout21.com':80
- http://go####hhalifax.com/wp-content/yTmYyLbTKZV2czsUO/
- http://x1.#.lencr.org/
- http://r3.#.lencr.org/MFMwUTBPME0wSzAJBgUrDgMCGgUABBRI2smg%2ByvTLU%2Fw3mjS9We3NfmzxAQUFC6zF7dYVsuuUAlA5h%2BvnYsUwsYCEgSTblOBEiTYJqJBsDUiD5fGLA%3D%3D
- http://r3.#.lencr.org/MFMwUTBPME0wSzAJBgUrDgMCGgUABBRI2smg%2ByvTLU%2Fw3mjS9We3NfmzxAQUFC6zF7dYVsuuUAlA5h%2BvnYsUwsYCEgMZC%2FnQtYfoYrl4HXdhg4aACA%3D%3D
- http://oc##.thawte.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQwF4prw9S7mCbCEHD%2Fyl6nWPkczAQUe1tFz6%2FOy3r9MZIaarbzRutXSFACEEeXTXhzpbyrDS%2BzcBkvzl4%3D
- http://ha###mout21.com/jetpack-temp/Py/
- 'go####hhalifax.ca':443
- 'tx###escue.com':443
- DNS ASK el###tech.com
- DNS ASK go####hhalifax.com
- DNS ASK go####hhalifax.ca
- DNS ASK x1.#.lencr.org
- DNS ASK r3.#.lencr.org
- DNS ASK tx###escue.com
- DNS ASK oc##.thawte.com
- DNS ASK ha###mout21.com
- '%WINDIR%\syswow64\regsvr32.exe' -s ..\xewn.dll' (со скрытым окном)