Техническая информация
- '<SYSTEM32>\wscript.exe' %TEMP%\3BZ.js
- %TEMP%\3bz.js
- http://dy####.0k7qo4r.buzz/?1/
- DNS ASK dy####.0k7qo4r.buzz
- DNS ASK cl###flare.com
- '<SYSTEM32>\cmd.exe' /S /D /c" sEt/p I4GND="%LRDH:fb56=%%1517:GBVBY=/%" 0<nul 1>%TEMP%\3BZ%EDZ%s"
- '<SYSTEM32>\cmd.exe' /S /D /c" md \ |"
- '<SYSTEM32>\cmd.exe' /S /D /c" echo stArt wsCript.eXe %TEMP%\3BZ%EDZ%s"
- '<SYSTEM32>\cmd.exe'