Техническая информация
- %WINDIR%\syswow64\rundll32.exe
- %TEMP%\~339706.tmp
- %TEMP%\~339706.tmp
- 'co##############e-chains.prod.autograph.services.mozaws.net':443
- 'ho####enpost.org':80
- http://ho####enpost.org/uploads/8a74d9577e1473b613fab8e0a3d3a7b6.png
- '34.##9.100.209':443
- DNS ASK vm######.hosting24.com.au
- DNS ASK co##############e-chains.prod.autograph.services.mozaws.net
- DNS ASK ho####enpost.org
- '%WINDIR%\syswow64\rundll32.exe' shell32.dll,Control_RunDLL
- '%WINDIR%\syswow64\cmd.exe' /C SYSTEMINFO && SYSTEMINFO && SYSTEMINFO && SYSTEMINFO && SYSTEMINFO && DEL "<Полный путь к файлу>" (со скрытым окном)
- '%WINDIR%\syswow64\systeminfo.exe'