Техническая информация
- %WINDIR%\syswow64\svchost.exe
- %TEMP%\aut5697.tmp
- %TEMP%\exhilaratingly
- %ALLUSERSPROFILE%\remcos\logs.dat
- %TEMP%\aut5697.tmp
- 'vl###mex.com.mx':2405
- 'ge###ugin.net':80
- http://ge###ugin.net/json.gp
- 'vl###mex.com.mx':2405
- DNS ASK vl###mex.com.mx
- DNS ASK ge###ugin.net
- '%WINDIR%\syswow64\svchost.exe'