Техническая информация
- '%WINDIR%\syswow64\taskkill.exe' /f /im "praetorian.exe"
- %TEMP%\kopatel-4it-na-moneti.exe
- %TEMP%\hjapbytav.exe
- %TEMP%\oqqfkatb.bat
- <DRIVERS>\etc\hоsts
- '255.255.255.255':80
- DNS ASK kr###lkd.net
- DNS ASK sr#.#ippro.ru
- ClassName: 'EDIT' WindowName: ''
- ClassName: '' WindowName: ''
- '%TEMP%\hjapbytav.exe' oqqfkatb.bat++kopatel-4it-na-moneti.exe++++++++++++
- '%TEMP%\kopatel-4it-na-moneti.exe'
- '%WINDIR%\syswow64\cmd.exe' /c ""%TEMP%\oqqfkatb.bat" " (со скрытым окном)
- '%WINDIR%\syswow64\chcp.com' 866