Техническая информация
- '<SYSTEM32>\cmd.exe' /c ping 127.0.0.1 -n 10 > nul & start C:\Users\Public\document.exe
- nul
- http://x.##2.us/x.cer
- http://o.##2.us//MEowSDBGMEQwQjAJBgUrDgMCGgUABBSLwZ6EW5gdYc9UaSEaaLjjETNtkAQUv1%2B30c7dH4b0W1Ws3NcQwg6piOcCCQCnDkpMNIK3fw%3D%3D
- http://oc##.###tg2.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBSIfaREXmfqfJR3TkMYnD7O5MhzEgQUnF8A36oB1zArOIiiuG1KnPIRkYMCEwZ%2FlEoqJ83z%2BsKuKwH5CO65xMY%3D
- http://oc##.####ca1.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBRPWaOUU8%2B5VZ5%2Fa9jFTaU9pkK3FAQUhBjMhTTsvAyUlC4IWZzHshBOCggCEwZ%2FlFeFh%2Bisd96yUzJbvJmLVg0%3D
- http://cr#.####ca1.amazontrust.com/rootca1.crl
- http://oc##.###1b.amazontrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQz9arGHWbnBV0DFzpNHz4YcTiFDQQUWaRmBlKge5WSPKOUByeWdFv5PdACEAFdfelN1gfXT68eCdFjXW0%3D
- http://cr#.####b.amazontrust.com/sca1b.crl
- http://oc##.#tartssl.com/sub/class2/code/ca/MEMwQTA%2FMD0wOzAJBgUrDgMCGgUABBQSOgrhRCSnWfKxoWTjWxhk8hga9AQU0E4PQJlsuEsZbzsouODjiAc0qrcCAhAV
- DNS ASK sh###.#etcloudapp.com
- DNS ASK x.##2.us
- DNS ASK o.##2.us
- DNS ASK oc##.###tg2.amazontrust.com
- DNS ASK oc##.####ca1.amazontrust.com
- DNS ASK cr#.####ca1.amazontrust.com
- DNS ASK oc##.###1b.amazontrust.com
- DNS ASK cr#.####b.amazontrust.com
- DNS ASK oc##.#tartssl.com
- '<SYSTEM32>\cmd.exe' /c ping 127.0.0.1 -n 10 > nul & start C:\Users\Public\document.exe' (со скрытым окном)
- '<SYSTEM32>\ping.exe' 127.0.0.1 -n 10