Техническая информация
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1464
- %APPDATA%\12433.xsl
- %TEMP%\966722.cvr
- %WINDIR%\temp\dhnr7.dll
- 'sa##ars.in':80
- http://www.sa##ars.in/wp-includes/js/tinymce/themes/inlite/Fj1Me7I5aqhuT.php
- DNS ASK ba####or-bdx.net
- DNS ASK sa##ars.in
- ClassName: 'ConsOleWindOWCLaSs' WindowName: ''
- '<SYSTEM32>\wbem\wmic.exe' (со скрытым окном)
- '<SYSTEM32>\rundll32.exe' C:/Windows/Temp//dhnr7.dll InitHelperDll