Timeline
- Infected by accessing: http://sansarall.ru/
- This link was found in the http code of the SPAM sent by win9 (e515267ba19417974a63b51e4f7dd9e9)
Mon Apr 20 14:31:32 CEST 2015
Start win8
Mon Apr 20 14:33:30 CEST 2015
Infected Did some connections and then nothing more.
Wed Apr 22 09:26:00 CEST 2015
poweroff