Техническая информация
- %WINDIR%\microsoft.net\framework\v4.0.30319\msbuild.exe
- %TEMP%\rarsfx0\dljcmajba74pe8g.exe
- %TEMP%\rarsfx0\pdf dropper.jpg
- %LOCALAPPDATA%\microsoft\clr_v4.0_32\usagelogs\dljcmajba74pe8g.exe.log
- DNS ASK ch####p.dyndns.org
- ClassName: 'Edit' WindowName: ''
- ClassName: 'NarratorUIClass' WindowName: ''
- '%TEMP%\rarsfx0\dljcmajba74pe8g.exe'
- '<SYSTEM32>\svchost.exe' -k appmodel -p -s camsvc
- '%WINDIR%\microsoft.net\framework\v4.0.30319\msbuild.exe'