Техническая информация
- $holispit как %temp%\anipaydnihs.exe
- '%WINDIR%\syswow64\cmd.exe' /C %tmp%\task.bat & UUUUUUUUc
- %TEMP%\task.bat
- %TEMP%\task (2).bat
- %TEMP%\task (2).bat
- 'gr###stalks.com':80
- 'ia####nsultants.com':80
- 'ia####nsultants.com':443
- http://gr###stalks.com/news.bin
- http://ia####nsultants.com/news.bin
- '34.##9.100.209':443
- 'ia####nsultants.com':443
- DNS ASK gr###stalks.com
- DNS ASK ia####nsultants.com
- '%WINDIR%\syswow64\cmd.exe' /C %tmp%\task.bat & UUUUUUUUc' (со скрытым окном)
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding