Техническая информация
- %WINDIR%\syswow64\cmd.exe
- %WINDIR%\syswow64\explorer.exe
- %TEMP%\c0cb24ff
- %TEMP%\biqpbnes
- '45.##2.112.131':80
- http://45.##2.112.131/
- http://45.##2.112.131/8dec448af1ff11b6/sqlite3.dll
- '%WINDIR%\syswow64\cmd.exe'
- '%WINDIR%\syswow64\explorer.exe'
- '%WINDIR%\syswow64\cmd.exe' /c timeout /t 5 & del /f /q "" & del "%ALLUSERSPROFILE%\*.dll"" & exit (со скрытым окном)
- '%WINDIR%\syswow64\timeout.exe' /t 5