Техническая информация
- '<SYSTEM32>\cmd.exe' \/\\ \ //\/\/ /V:ON/C"set +'[{=7a20 07a2 7a20 a720 a207 a702 207a a270 0a27 072a 702a 7a20 20a7 02a7 a027 07a2 70a2 270a}a720}07a2{720ah7a02c20a7t70a2a702aca702}a072;7a02k270aaa702e270ar0a27ba...
- C:\users\public\558.exe
- C:\users\public\558.exe
- C:\users\public\558.exe
- 'ac###gger.com':80
- 'yy##14.cn':80
- 'is#####ndustries.com':80
- 'is#####ndustries.com':443
- 'gr###rear.com':80
- http://ac###gger.com/LrIaq
- http://www.yy##14.cn/ox
- http://is#####ndustries.com/Fo
- http://gr###rear.com/3l
- http://gr###rear.com/3l/
- 'is#####ndustries.com':443
- DNS ASK ac###gger.com
- DNS ASK yy##14.cn
- DNS ASK is#####ndustries.com
- DNS ASK gr###rear.com
- DNS ASK re####haiduong.com
- '<SYSTEM32>\cmd.exe' \/\\ \ //\/\/ /V:ON/C"set +'[{=7a20 07a2 7a20 a720 a207 a702 207a a270 0a27 072a 702a 7a20 20a7 02a7 a027 07a2 70a2 270a}a720}07a2{720ah7a02c20a7t70a2a702aca702}a072;7a02k270aaa702e270ar0a27ba...' (со скрытым окном)