Technical Information
- '%TEMP%\qKahohVx.exe' x AxUZ.zip -pq1w2e3r4t5y6u7i8o9 -y
- '%TEMP%\qKahohVx.exe' (downloaded from the Internet)
- '<SYSTEM32>\cmd.exe' /k c: & cd\ & cd %HOMEPATH%\Local Settings\Temp & qKahohVx.exe x AxUZ.zip -pq1w2e3r4t5y6u7i8o9 -y & exit
- %TEMP%\AxUZ.zip
- %TEMP%\qKahohVx.exe
- 'ho####oodvips.com':80
- http://ho####oodvips.com/spaco/west.jpg
- http://ho####oodvips.com/liga/wosts.jpg
- DNS ASK ho####oodvips.com