Техническая информация
- %APPDATA%\kubikcentimeter.gua
- 'mi###aces.com':443
- 'x1.#.lencr.org':80
- 'mo####macktalk.com':443
- 'fi#####ocksmiths.co.uk':443
- '10#.#95.237.43':80
- http://x1.#.lencr.org/
- http://10#.#95.237.43/Serosa.mix
- 'mi###aces.com':443
- 'mo####macktalk.com':443
- 'fi#####ocksmiths.co.uk':443
- DNS ASK mi###aces.com
- DNS ASK x1.#.lencr.org
- DNS ASK mo####macktalk.com
- DNS ASK fi#####ocksmiths.co.uk
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' "cls;write 'Pariaers Slvfadene Frgemnds Salpetersyrefabrikken205 Blidhedens114 Feriegiros Austerer Unpendant Bestialiteter Polyethers Linkedit Endkkerne Threaded Produktions Keratoconus Cdu Ove... (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /c "echo %appdata%\Kubikcentimeter.Gua && echo t"
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' "cls;write 'Pariaers Slvfadene Frgemnds Salpetersyrefabrikken205 Blidhedens114 Feriegiros Austerer Unpendant Bestialiteter Polyethers Linkedit Endkkerne Threaded Produktions Keratoconus Cdu Ove...
- '%WINDIR%\syswow64\cmd.exe' /c "echo %appdata%\Kubikcentimeter.Gua && echo t"