Техническая информация
- '<SYSTEM32>\cmd.exe' /V /C set "C9bEpB=%APPDATA%\%RANDOM%.vbs" && (for %i in ("DIm Wxyu" "sUB SgC(NWQkv)" "IH=6" "DIm JdnXjKh" "K2IqW=60" "WO="LJ"" "Tkp1J=1" "SeT JdnXjKh=CReaTEObJEct(R25r("0B0805080862193838292B21...
- %APPDATA%\4247.vbs
- 'pa###louf.com':80
- '20#.#7.8.251':80
- http://pa###louf.com/data.bin
- DNS ASK pa###louf.com
- '<SYSTEM32>\wscript.exe' "%APPDATA%\4247.vbs"
- '<SYSTEM32>\cmd.exe' /V /C set "C9bEpB=%APPDATA%\%RANDOM%.vbs" && (for %i in ("DIm Wxyu" "sUB SgC(NWQkv)" "IH=6" "DIm JdnXjKh" "K2IqW=60" "WO="LJ"" "Tkp1J=1" "SeT JdnXjKh=CReaTEObJEct(R25r("0B0805080862193838292B21...' (со скрытым окном)