Техническая информация
- '%APPDATA%\microsoft\windows\printer shortcuts\gkwtijz.exe'
- drdfge.exe
- %APPDATA%\microsoft\windows\printer shortcuts\gkwtijz.exe
- %TEMP%\zurjgihj.cmd
- %TEMP%\drdfge.sfx.exe
- %TEMP%\drdfge.exe
- 'ba##rad.com':8091
- http://ba####d.com:8091/aorry/server1.exe via ba##rad.com
- DNS ASK ba##rad.com
- ClassName: 'EDIT' WindowName: ''
- '%TEMP%\drdfge.sfx.exe' -prythngogjfdngfszafugyRygfysrsoihfirsugsudbfrgsfskfshbrhhguhrhgnmeMv -d%LOCALAPPDATA%\Temp
- '%TEMP%\drdfge.exe'
- '%WINDIR%\syswow64\cmd.exe' /c ""%TEMP%\zurjgihj.cmd" "