Technical Information
- '%WINDIR%\explorer.exe' /c, %TEMP%\Lqixzzv.jS
- %TEMP%\lqixzzv.js
- DNS ASK 4a#######uekw.r4uamrr7fueez.cf
- '<SYSTEM32>\wscript.exe' "%TEMP%\Lqixzzv.Js"
- '<SYSTEM32>\wscript.exe' "%TEMP%\Lqixzzv.Js"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /S /D /c" sET/p UUFIIHH="%IKG:JJLN=%%d225777:PZT=/%" 0<nul 1>%TEMP%\Lqixzzv.Js 2>&1"
- '<SYSTEM32>\cmd.exe' /S /D /c" CAll %GGE:VAAD=% %TEMP%\Lqixzzv.jS 2>&1"
- '<SYSTEM32>\cmd.exe' /S /D /c" exiT"