Technical Information
- %TEMP%\814129322
- %TEMP%\nsoe755.tmp\system.dll
- %TEMP%\fno18dhjs
- DNS ASK ne####ndfriend.xyz
- '%WINDIR%\syswow64\cmd.exe' /S /C choice /C hY /N h/D Y h/T 3 & Del "<Full path to file>"' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /S /C choice /C hY /N h/D Y h/T 3 & Del "<Full path to file>"
- '%WINDIR%\syswow64\choice.exe' /C hY /N h/D Y h/T 3