Техническая информация
- '<SYSTEM32>\wscript.exe' %TEMP%\twu.js
- %TEMP%\twu.js
- http://0r####.l13hjhebfkzz.net/?1/
- DNS ASK 0r####.l13hjhebfkzz.net
- '<SYSTEM32>\cmd.exe' /S /D /c" sEt/p 4GYBN="%NCYI:2YOp=%%K3LB:VSOMY=/%" 0<nul 1>%TEMP%\twu%ROJ%s"
- '<SYSTEM32>\cmd.exe' /S /D /c" md \ |"
- '<SYSTEM32>\cmd.exe' /S /D /c" echo stArt <SYSTEM32>\wsCript.eXe %TEMP%\twu%ROJ%s"
- '<SYSTEM32>\cmd.exe'