Техническая информация
- %WINDIR%\syswow64\zijjll.bat
- nul
- 'xz###vc.net.cn':8080
- 'xz###vc.net.cn':80
- http://17#.##.130.59:8080/sports/image.jpg
- http://17#.#7.130.59/files/image.jpg
- http://17#.##.130.59:8080/news/image.jpg
- http://17#.#7.130.59/nba/image.jpg
- DNS ASK xz###vc.net.cn
- '%WINDIR%\syswow64\cmd.exe' /c <SYSTEM32>\zijjll.bat (со скрытым окном)
- '%WINDIR%\syswow64\ping.exe' -n 3 127.0.0.1