Техническая информация
- '<SYSTEM32>\cmd.exe' /c start /min "" Powershell.exe -ExecutionPolicy ByPass -WindowStyle hidden -command Rundll32.exe %TEMP%\Prozorro.zip,StartW
- %TEMP%\prozorro.zip
- 'mi####ssally.com':80
- 'mi####ssally.com':443
- http://mi####ssally.com/jMnmopzu
- 'mi####ssally.com':443
- DNS ASK mi####ssally.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ExecutionPolicy ByPass -WindowStyle hidden -command Rundll32.exe %TEMP%\Prozorro.zip,StartW
- '<SYSTEM32>\rundll32.exe' %TEMP%\Prozorro.zip StartW