Техническая информация
- [<HKLM>\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\run] '' = '<DRIVERS>\nwrdtdrv.exe'
- <SYSTEM32>\wsx1.exe
- %WINDIR%\sleep.exe 500
- <SYSTEM32>\cmd.exe /c %TEMP%\temp8254.bat
- %TEMP%\temp8254.bat
- <SYSTEM32>\wsx1.exe
- 'no####s.no-ip.biz':5558
- DNS ASK no####s.no-ip.biz