Техническая информация
- '<SYSTEM32>\regsvr32.exe' C:\Datop\besta.ocx
- '<SYSTEM32>\regsvr32.exe' C:\Datop\bestb.ocx
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 672
- %TEMP%\1478140.cvr
- 'ib##b.org':443
- 'x1.#.lencr.org':80
- 'r3.#.lencr.org':80
- 'fu######rothersconcrete.com':443
- 'tr#####erresorts.com':443
- 'oc##.#tartssl.com':80
- http://x1.#.lencr.org/
- http://r3.#.lencr.org/MFMwUTBPME0wSzAJBgUrDgMCGgUABBRI2smg%2ByvTLU%2Fw3mjS9We3NfmzxAQUFC6zF7dYVsuuUAlA5h%2BvnYsUwsYCEgOM%2Fs4cn0F9M49E%2Fw6FAYm6aQ%3D%3D
- http://oc##.#tartssl.com/sub/class2/code/ca/MEMwQTA%2FMD0wOzAJBgUrDgMCGgUABBQSOgrhRCSnWfKxoWTjWxhk8hga9AQU0E4PQJlsuEsZbzsouODjiAc0qrcCAhAV
- 'ib##b.org':443
- 'fu######rothersconcrete.com':443
- 'tr#####erresorts.com':443
- DNS ASK ib##b.org
- DNS ASK x1.#.lencr.org
- DNS ASK r3.#.lencr.org
- DNS ASK fu######rothersconcrete.com
- DNS ASK tr#####erresorts.com
- DNS ASK oc##.#tartssl.com