Technical Information
- %WINDIR%\syswow64\windowspowershell\v1.0\efsane.bat
 - %WINDIR%\syswow64\windowspowershell\v1.0\kedi.jpeg
 - nul
 - %TEMP%\~ptr_b.tmp
 - %TEMP%\~ptr_b.bat
 - %WINDIR%\temp\client.exe
 
- 'gi##ub.com':443
 - 'ra#.####ubusercontent.com':443
 - 'localhost':9875
 - '31.##.187.119':9875
 
- 'gi##ub.com':443
 - 'ra#.####ubusercontent.com':443
 - '31.##.187.119':9875
 
- DNS ASK gi##ub.com
 - DNS ASK ra#.####ubusercontent.com
 
- ClassName: 'EDIT' WindowName: ''
 - ClassName: 'NarratorUIClass' WindowName: ''
 
- '%WINDIR%\temp\client.exe'
 
- '%WINDIR%\syswow64\cmd.exe' /c ""<SYSTEM32>\WindowsPowerShell\v1.0\Efsane.bat" "
 - '<SYSTEM32>\svchost.exe' -k appmodel -p -s camsvc
 - '%WINDIR%\syswow64\chcp.com' 65001
 - '%WINDIR%\syswow64\timeout.exe' /t 0
 - '%WINDIR%\syswow64\cmd.exe' /c exit 0
 - '%WINDIR%\syswow64\certutil.exe' -decode "%TEMP%\~ptr_b.tmp" "%TEMP%\~ptr_b.bat"
 - '%WINDIR%\temp\client.exe' ' (with hidden window)