Техническая информация
- <SYSTEM32>\rundll32.exe "%TEMP%\ins1.tmp",yohoyjvpy install
- %TEMP%\ins1.tmp
- 'ho##.cz.cc':80
- ho##.cz.cc/YjrcOgctOv2hg28eM7AOuPsyFClseqWn60dhLvOJuIGletkjY2jZvknFT5xB0Yy2uyI92o0rO+0LiqRvG0UpGnAhOfY9NsEP5K7761sP68o=
- ho##.cz.cc/KeZCNTXlNJnvN3qd78WltQfBFO9AcLouogymo4OJ821qc519RXQCUiZCVEl5JGKjQlCJmJr3uK4XhyJAOVw1ruWJtAGX/HpXLvRvmN3lZLHx2aBAI0zEAi/Ozs8w9WSKMiC3Rp/UYtoVT2FFZJitjL2nOgzmPh+xLVnF1f0vmUEXbPESU/qJeGyMf1onfjYcrOA2dwpx
- DNS ASK ho##.cz.cc
- '<IP-адрес в локальной сети>':1036
- ClassName: 'Shell_TrayWnd' WindowName: ''