Техническая информация
- %WINDIR%\syswow64\dm.dll
- %TEMP%\933c.tmp
- %TEMP%\932a.tmp
- 'do##an.com':443
- 'ra#.####ubusercontent.com':443
- 'my####ication.top':80
- 'ls###960417.com':80
- http://www.my####ication.top/adcheatReserved/test_ed_403.html
- http://www.ls###960417.com/adcheatReserved/test_ed_403.html
- 'do##an.com':443
- 'ra#.####ubusercontent.com':443
- DNS ASK do##an.com
- DNS ASK ra#.####ubusercontent.com
- DNS ASK my####ication.top
- DNS ASK ls###960417.com
- DNS ASK ls###960417.cn
- '%WINDIR%\syswow64\regsvr32.exe' <SYSTEM32>\dm.dll /s