Техническая информация
- %TEMP%\sample.exe
- %TEMP%\bitmap2.bat
- %TEMP%\sbq3nwrir35b.bat
- %APPDATA%\folder0\08-10-2023
- nul
- 'ip##pi.com':80
- 'fr###eoip.net':80
- 'ap#.#pify.org':80
- http://ip##pi.com/json/
- http://fr###eoip.net/xml/
- http://fr###eoip.net/shutdown
- http://ap#.#pify.org/
- DNS ASK ip##pi.com
- DNS ASK fr###eoip.net
- DNS ASK ap#.#pify.org
- '%WINDIR%\syswow64\cmd.exe' /c ""%TEMP%\sBq3NWrir35b.bat" "' (со скрытым окном)
- '%WINDIR%\syswow64\cmd.exe' /c ""%TEMP%\sBq3NWrir35b.bat" "
- '%WINDIR%\syswow64\chcp.com' 65001
- '%WINDIR%\syswow64\ping.exe' -n 10 localhost