Technical Information
- '%TEMP%\rCOestyhxQPSEl.exe' x zKpNDQb.zip -pq1w2e3r4t5y6u7i8o9 -y
- '%TEMP%\rCOestyhxQPSEl.exe' (downloaded from the Internet)
- '<SYSTEM32>\cmd.exe' /k c: & cd\ & cd %HOMEPATH%\Local Settings\Temp & rCOestyhxQPSEl.exe x zKpNDQb.zip -pq1w2e3r4t5y6u7i8o9 -y & exit
- %TEMP%\zKpNDQb.zip
- %TEMP%\rCOestyhxQPSEl.exe
- 'www.me###nettes.com':80
- http://www.me###nettes.com/content/modules/1-9/chin/chin/petro.jpg
- http://www.me###nettes.com/content/modules/1-9/chin/chin/7za.jpg
- DNS ASK www.me###nettes.com