Technical Information
- '18#.#22.58.56':80
- http://18#.#22.58.56/Ldepbhr_Khjccjyp.bmp
- '%WINDIR%\syswow64\cmd.exe' /c timeout 20' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c timeout 35' (with hidden window)
- '%WINDIR%\syswow64\cmd.exe' /c timeout 20
- '%WINDIR%\syswow64\timeout.exe' 20
- '%WINDIR%\syswow64\cmd.exe' /c timeout 35
- '%WINDIR%\syswow64\timeout.exe' 35