Technical Information
- '' (downloaded from the Internet)
- '%APPDATA%\bonxn3267.exe'
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' Add-MpPreference -ExclusionPath '%APPDATA%\bonxn3267.exe'
- bonxn3267.exe
- %APPDATA%\bonxn3267.exe
- http://go##dns.ir/basara/bonx.exe
- DNS ASK go##dns.ir
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding