Техническая информация
- <SYSTEM32>\rundll32.exe "%TEMP%\ins1.tmp",ugcokbfhub install
- %TEMP%\ins1.tmp
- 'el####thwete.co.be':80
- el####thwete.co.be/agfgWIkimV+cjEiK/NJ/9/kpEvvd6KW4ZGdwVkqDgLqQ23wfr+9p3UEfH2D0pCTTPZDpElnUbMfDHdN+ZzC7ADxzXUw7k/tqj2p7fktCFmkIQA==
- el####thwete.co.be/fMOVlKPTMs0MwMGWyvoE70DzW0+tmVqhD4Lk9S8YAsOvpF7C+xubvOt9MShP+4wdYX8hsd2oQm6M+GrfVou12ZoCgRN1uJVgVC5NOZTAtuy0+93CRvzlxEd0oiygTIfiKdk0AaHhijIZhst98hZ2iDEJTMlSDfKigG/l+ty1PLBJMBW/YS5QZ9FGTwSzU4q1KH/J6On8G9k=
- DNS ASK el####thwete.co.be
- '<IP-адрес в локальной сети>':1037
- ClassName: 'Shell_TrayWnd' WindowName: ''