Technical Information
- %TEMP%\rad6be12.tmp
- %TEMP%\rad6be12.tmp
- '13##.######ngs.love4lifewellness.com':443
- '13##.######ngs.love4lifewellness.com':443
- DNS ASK 13##.######ngs.love4lifewellness.com
- '<SYSTEM32>\cmd.exe' /C whoami /all >> "%TEMP%\rad6BE12.tmp"' (with hidden window)
- '<SYSTEM32>\cmd.exe' /C whoami /all >> "%TEMP%\rad6BE12.tmp"
- '<SYSTEM32>\whoami.exe' /all