Техническая информация
- %TEMP%\ixp000.tmp\ifsa.bat
- nul
- %TEMP%\~ptr_x.tmp
- %TEMP%\~ptr_x.bat
- %TEMP%\ixp000.tmp\ifsa.bat
- DNS ASK gi##ub.com
- '<SYSTEM32>\cmd.exe' /c "ifsa.bat"
- '<SYSTEM32>\chcp.com' 65001
- '<SYSTEM32>\cmd.exe' /c exit 0
- '<SYSTEM32>\timeout.exe' /t 0
- '<SYSTEM32>\certutil.exe' -decode "%TEMP%\~ptr_x.tmp" "%TEMP%\~ptr_x.bat"