Техническая информация
- '<SYSTEM32>\cscript.exe' /nologo C:\Users\Public\tmpdirectory\d.vbs
- '<SYSTEM32>\regsvr32.exe' /si %TEMP%\d.dll
- C:\users\public\tmpdirectory\d.vbs
- C:\users\public\tmpdirectory\d.vbs
- http://bi###irock.club/campo/1594668998/0GAOuKlsBwbZXTYE6/fGcPRAeCY0z3Jmt
- DNS ASK bi###irock.club