Техническая информация
- '<SYSTEM32>\regsvr32.exe' /S ..\elv1.ooocccxxx
- '<SYSTEM32>\regsvr32.exe' /S ..\elv2.ooocccxxx
- '<SYSTEM32>\regsvr32.exe' /S ..\elv3.ooocccxxx
- '<SYSTEM32>\regsvr32.exe' /S ..\elv4.ooocccxxx
- %HOMEPATH%\elv2.ooocccxxx
- <Текущая директория>\6b4d0000
- <PATH_SAMPLE>.xls
- 'gr#####lleyschool.com':443
- 'hs###xintp.com':80
- 'ch####ngsoftech.com':80
- 'ch####ngsoftech.com':443
- 'x1.#.lencr.org':80
- 'bw#####neering.co.za':80
- http://hs###xintp.com/wp-admin/NP0kMO3VgxpmpkJ/
- http://www.ch####ngsoftech.com/AMMAN/bUM7CGZ4NB2vAiJMPi/
- http://x1.#.lencr.org/
- http://bw#####neering.co.za/configSHV/ot3TehH82zNjjRPuFKH/
- 'gr#####lleyschool.com':443
- 'ch####ngsoftech.com':443
- DNS ASK gr#####lleyschool.com
- DNS ASK hs###xintp.com
- DNS ASK ch####ngsoftech.com
- DNS ASK x1.#.lencr.org
- DNS ASK bw#####neering.co.za
- '<SYSTEM32>\regsvr32.exe' /S ..\elv1.ooocccxxx' (со скрытым окном)
- '<SYSTEM32>\regsvr32.exe' /S ..\elv2.ooocccxxx' (со скрытым окном)
- '<SYSTEM32>\regsvr32.exe' /S ..\elv3.ooocccxxx' (со скрытым окном)
- '<SYSTEM32>\regsvr32.exe' /S ..\elv4.ooocccxxx' (со скрытым окном)