Техническая информация
- '<SYSTEM32>\regsvr32.exe' ..\hvxda.ocx
- %HOMEPATH%\hvxda.ocx
- <Текущая директория>\93031000
- <PATH_SAMPLE>.xls
- 'pr####ichemfood.com':80
- 'pr####ichemfood.com':443
- 'lo#####blicidade.com':443
- 'bo##y.com':443
- 'st####.thawte.com':80
- 'cd#.#hawte.com':80
- 'se#####solutions.com':80
- http://pr####ichemfood.com/wp-content/Mwmos/
- http://st####.thawte.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSFvn094QJ%2BcWGTwWWEy%2BBXPZkW8AQUo8heZVTlMHjBBeoHCmpZzLn%2B3loCEAfEdUhhCKkCz14oKMmOE8c%3D
- http://cd#.#hawte.com/ThawteRSACA2018.crl
- http://se#####solutions.com/cgi-bin/WLoO6sEzYCJ3LTlC/
- http://se#####solutions.com/cgi-sys/suspendedpage.cgi
- 'pr####ichemfood.com':443
- 'lo#####blicidade.com':443
- 'bo##y.com':443
- DNS ASK pr####ichemfood.com
- DNS ASK lo#####blicidade.com
- DNS ASK bo##y.com
- DNS ASK st####.thawte.com
- DNS ASK cd#.#hawte.com
- DNS ASK se#####solutions.com
- '<SYSTEM32>\regsvr32.exe' ..\hvxda.ocx' (со скрытым окном)