Technical Information
- %WINDIR%\explorer.exe
- %TEMP%\~224557.tmp
- %TEMP%\~224557.tmp
- DNS ASK un#####tportugal.co.uk
- '<SYSTEM32>\cmd.exe' /C SYSTEMINFO && SYSTEMINFO && SYSTEMINFO && SYSTEMINFO && SYSTEMINFO && DEL "<Full path to file>"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /C SYSTEMINFO && SYSTEMINFO && SYSTEMINFO && SYSTEMINFO && SYSTEMINFO && DEL "<Full path to file>"
- '<SYSTEM32>\systeminfo.exe'