Technical Information
- %WINDIR%\syswow64\windowspowershell\v1.0\9c85b6d.exe
- %TEMP%\9096.bat
- 'dl.###bufferbox.com':80
- 'cr############allback.s3-us-west-2.amazonaws.com':80
- DNS ASK er####.crossrider.com
- DNS ASK dl.###bufferbox.com
- DNS ASK cr############allback.s3-us-west-2.amazonaws.com
- '%WINDIR%\syswow64\windowspowershell\v1.0\9c85b6d.exe' "<Full path to file>"
- '%WINDIR%\syswow64\cmd.exe' /c ""%TEMP%\9096.bat" "%WINDIR%\SysWOW64\WindowsPowerShell\v1.0\9c85b6d.exe""
- '%WINDIR%\syswow64\windowspowershell\v1.0\9c85b6d.exe' "<Full path to file>"' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c ""%TEMP%\9096.bat" "%WINDIR%\SysWOW64\WindowsPowerShell\v1.0\9c85b6d.exe""' (with hidden window)