Technical Information
- '' (downloaded from the Internet)
- '%APPDATA%\damiano12345.exe'
- %APPDATA%\damiano12345.exe
- 'ch###.#habigroup.top':80
- http://ch###.#habigroup.top/_errorpages/damianoPKzx.exe
- DNS ASK ch###.#habigroup.top
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding