Техническая информация
- %APPDATA%\jaded.bfk
- 'ta###chutz.org':80
- http://ta###chutz.org/wsb642884001/befalede.jpb
- DNS ASK ta###chutz.org
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' "Function Rgfanernes9 ([String]$Konsummlken){For($Astricted=1; $Astricted -lt $Konsummlken.Length-1; $Astricted+=(1+1)){$Sandiver=$Sandiver+$Konsummlken.Substring( $Astricted, 1)};$Sand...' (со скрытым окном)
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' "Function Rgfanernes9 ([String]$Konsummlken){For($Astricted=1; $Astricted -lt $Konsummlken.Length-1; $Astricted+=(1+1)){$Sandiver=$Sandiver+$Konsummlken.Substring( $Astricted, 1)};$Sand...
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' "Function Bailiary02([String]$Frgendes) { $Cumulately = [System.Byte[]]::CreateInstance([System.Byte],$Frgendes.Length / 2) $Meadowland = (cmd /c 'echo 16') For($Dramaserie=0; $Dramaserie -...
- '%WINDIR%\syswow64\cmd.exe' /c "echo 16"