Техническая информация
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1468
- %APPDATA%\ce13.xsl
- %TEMP%\974616.cvr
- 'gr###jukes.com':443
- 'cu###dscrew.com':443
- 'we####ssway.co.za':443
- 'he###long.com':80
- http://he###long.com/NJm75ajGNU.php
- 'gr###jukes.com':443
- DNS ASK ho#####dblessing.com
- DNS ASK go###llet.com
- DNS ASK or####onsulting.com
- DNS ASK gr###jukes.com
- DNS ASK cu###dscrew.com
- DNS ASK ku###oding.com
- DNS ASK dr###itelite.it
- DNS ASK ea###eber.net
- DNS ASK we####ssway.co.za
- DNS ASK he###long.com
- ClassName: 'CONSoLewInDowCLASS' WindowName: ''
- '<SYSTEM32>\wbem\wmic.exe' (со скрытым окном)