Technical Information
- DNS ASK ss####ahotie.top
- '<SYSTEM32>\cmd.exe' /c ^Cd^ %LocALapPdata%.exeChej^orUw^D^uHuhzE^nEdhA^mXa^GMab^D^EBcYdf^ol^PA^d^h^opo^cNy^Tmo^mu^hv^o^rUHU^Vt^ECtEkcUBJuzb^AP^HOL^ernu^kI^JpI^gVO^RrE^F^ega^M^r^aXDoV^YJqa^c^R^aHd^o^lZAj^JU^V^I^SiH...' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c ^Cd^ %LocALapPdata%.exeChej^orUw^D^uHuhzE^nEdhA^mXa^GMab^D^EBcYdf^ol^PA^d^h^opo^cNy^Tmo^mu^hv^o^rUHU^Vt^ECtEkcUBJuzb^AP^HOL^ernu^kI^JpI^gVO^RrE^F^ega^M^r^aXDoV^YJqa^c^R^aHd^o^lZAj^JU^V^I^SiH...