Technical Information
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1472
- %APPDATA%\1f003.xsl
- %TEMP%\1113659.cvr
- 'we####ssway.co.za':443
- 'yo#####suratkumar.com':443
- 'ab##it.com':443
- 'x1.#.lencr.org':80
- http://x1.#.lencr.org/
- 'yo#####suratkumar.com':443
- 'ab##it.com':443
- DNS ASK ho#####dblessing.com
- DNS ASK we####ssway.co.za
- DNS ASK mi###pharma.com
- DNS ASK us###tnet.co.uk
- DNS ASK dr###itelite.it
- DNS ASK ku###oding.com
- DNS ASK te###urver.nl
- DNS ASK yo#####suratkumar.com
- DNS ASK go###llet.com
- DNS ASK ab##it.com
- DNS ASK x1.#.lencr.org
- ClassName: 'COnSoLewInDoWClasS' WindowName: ''
- '<SYSTEM32>\wbem\wmic.exe'
- '<SYSTEM32>\wbem\wmic.exe' ' (with hidden window)