Техническая информация
- %WINDIR%\udiwi
- %TEMP%\nsd3b7.tmp\twkgr.exe
- %TEMP%\nsd3b7.tmp\simplefc.dll
- %LOCALAPPDATA%\microsoft\clr_v4.0_32\usagelogs\twkgr.exe.log
- %TEMP%\nsd3b7.tmp\simplefc.dll
- %TEMP%\nsd3b7.tmp\twkgr.exe
- 'np##.site':80
- http://www.np##.site/mwzzj0vk7
- DNS ASK np##.site
- '%TEMP%\nsd3b7.tmp\twkgr.exe' "http://www.npmk.site/mwzzj0vk7" "%TEMP%\nsd3B7.tmp\Houseguests.exe" "bcqwj"
- '%TEMP%\nsd3b7.tmp\twkgr.exe' "mwzzj0vk7" "%TEMP%\nsd3B7.tmp\cvybdj"